plugin

Google Sitemap Generator Vulnerabilities

7 known security issues reported for the Google Sitemap Generator WordPress plugin. Most recent disclosed Dec 16, 2025.

3 medium

Running Google Sitemap Generator on your site? Check whether your installed version is affected.

Scan your site free

XML Sitemap Generator for Google [google-sitemap-generator] <= 4.1.21 (unfixed)

unknown

[en] Missing Authorization vulnerability in Auctollo Google XML Sitemaps google-sitemap-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google XML Sitemaps: from n/a through <= 4.1.21.

Affected:
up to 4.1.21
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-64632 on NVD →

Google XML Sitemaps <= 4.1.22 - Missing Authorization

medium

The Google XML Sitemaps plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.22. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.1.22
Fixed in:
4.1.23
Disclosed:
Oct 31, 2025

CVE-2025-64632 on NVD →

XML Sitemap Generator for Google [google-sitemap-generator] < 4.1.3

unknown

[en] The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 4.1.3
Fixed in:
4.1.3
Disclosed:
Jun 20, 2022

CVE-2021-25088 on NVD →

XML Sitemaps <= 4.1.1 - Authenticated (Admin+) Cross-Site Scripting

medium

The XML Sitemaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.1.1 due to insufficient input sanitization and output escaping on the Debug page. This makes it possible for authenticated attackers with administrative level permissions and abo...

CVSS:
5.5
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
May 30, 2022

CVE-2021-25088 on NVD →

XML Sitemap Generator for Google [google-sitemap-generator] < 4.1.0

unknown

[en] Cross-site scripting vulnerability in Google XML Sitemaps Version 4.0.9 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
Jan 9, 2019

CVE-2018-16204 on NVD →

XML Sitemaps <= 4.0.9 - Authenticated Cross-Site Scripting

medium

Cross-site scripting vulnerability in Google XML Sitemaps Version 4.0.9 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
5.5
Affected:
up to 4.0.9
Fixed in:
4.1.0
Disclosed:
Dec 25, 2018

CVE-2018-16204 on NVD →

XML Sitemap Generator for Google [google-sitemap-generator] < 4.0.9

unknown

The plugin contains a Paypal donate button that is echoing the global variable HTTP_HOST, which can be manipulated by the visitor. Vulnerable Code: sitemap-ui.php L1310 echo &#039;http://&#039; . $_SERVER[&#039;HTTP_HOST&#039;]...

Affected:
up to 4.0.9
Fixed in:
4.0.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database