VDB
CVE-2021-36912
CVE-2021-36912
PUBLISHED
CVSS 5.400000095367432 MEDIUM
Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role.
EPSS 0.56% · 45.5th percentile
Risk Scores
CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.56%
45.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Andrea Pernici | Andrea Pernici News Sitemap for Google (WordPress plugin) | <= 1.0.16 |
| google-news-sitemap_project | google-news-sitemap | 0 |
Timeline
- May 6, 2022 CVE Published
- May 8, 2022 EPSS Score
- Jun 27, 2022 EPSS Score
- Aug 17, 2022 EPSS Score
- Oct 5, 2022 EPSS Score
- Nov 24, 2022 EPSS Score
- Jan 13, 2023 EPSS Score
- Mar 4, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 23, 2023 EPSS Score
- Jun 11, 2023 EPSS Score
- Jul 31, 2023 EPSS Score
References
- https://patchstack.com/database/vulnerability/google-news-sitemap/wordpress-andrea-pernici-news-sitemap-for-google-plugin-1-0-16-authenticated-stored-cross-site-scripting-xss-vulnerability url
- https://nvd.nist.gov/vuln/detail/CVE-2021-36912 advisory
- https://wordpress.org/plugins/google-news-sitemap url
- https://wordpress.org/plugins/google-news-sitemap/ vendor