{"api_version":"1","generated_at":"2026-07-23T20:59:00+00:00","cve":"CVE-2022-0230","urls":{"html":"https://cve.report/CVE-2022-0230","api":"https://cve.report/api/cve/CVE-2022-0230.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-0230","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-0230"},"summary":{"title":"CVE-2022-0230","description":"The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2022-03-14 15:15:00","updated_at":"2022-03-21 05:19:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/c73316d2-ae6a-42db-935b-b8b03a7e4363","name":"https://wpscan.com/vulnerability/c73316d2-ae6a-42db-935b-b8b03a7e4363","refsource":"MISC","tags":[],"title":"Better WordPress Google XML Sitemaps <= 1.4.1 - Unauthenticated Stored Cross-Site Scripting WordPress Security Vulnerability","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-0230","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0230","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Krzysztof Zając","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"230","vulnerable":"1","versionEndIncluding":"1.4.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bwp-google-xml-sitemaps_project","cpe5":"bwp-google-xml-sitemaps","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2022-0230","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC","TITLE":"Better WordPress Google XML Sitemaps <= 1.4.1 - Unauthenticated Stored Cross-Site Scripting"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","generator":"WPScan CVE Generator","affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"Better WordPress Google XML Sitemaps (support Sitemap Index, Multi-site and Google News)","version":{"version_data":[{"version_affected":"<=","version_name":"1.4.1","version_value":"1.4.1"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins"}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://wpscan.com/vulnerability/c73316d2-ae6a-42db-935b-b8b03a7e4363","name":"https://wpscan.com/vulnerability/c73316d2-ae6a-42db-935b-b8b03a7e4363"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"CWE-79 Cross-site Scripting (XSS)","lang":"eng"}]}]},"credit":[{"lang":"eng","value":"Krzysztof Zając"}],"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-03-14 15:15:00","lastModifiedDate":"2022-03-21 05:19:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bwp-google-xml-sitemaps_project:bwp-google-xml-sitemaps:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"1.4.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"230","Ordinal":"225902","Title":"CVE-2022-0230","CVE":"CVE-2022-0230","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"230","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}