Google XML Sitemaps Generator < 3.2.9 - Authenticated (Admin+) PHP Code Injection
highThe Google XML Sitemaps Generator plugin for WordPress is vulnerable to PHP Code Injection in versions before 3.2.9 via the 'sm_cf_home' and 'sm_cf_posts' parameters. This allows authenticated attackers with admin-level privileges to inject code onto the server.
- CVSS:
- 7.2
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.9
- Disclosed:
- Jan 8, 2013