WP HTML Sitemap <= 1.2 - Cross-Site Request Forgery
mediumCross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete the sitemap via a request to the wp-html-sitemap page in wp-admin/options-general.php.
- CVSS:
- 6.5
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 1, 2014