.. / CVE-2022-0346

Exploit for WordPress XML Sitemap Generator for Google <2.0.4 - Cross-Site Scripting/Remote Code Execution (CVE-2022-0346)

Description:

WordPress XML Sitemap Generator for Google plugin before 2.0.4 contains a cross-site scripting vulnerability that can lead to remote code execution. It does not validate a parameter which can be set to an arbitrary value, thus causing cross-site scripting via error message or remote code execution if allow_url_include is turned on.

Nuclei Template

View the template here CVE-2022-0346.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0346.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2022-0346
https://wordpress.org/plugins/www-xml-sitemap-generator-org/
https://github.com/ARPSyndicate/kenzer-templates
https://wpscan.com/vulnerability/4b339390-d71a-44e0-8682-51a12bd2bfe6