WPIntell

Source evidence

security risk reported by WP Engine

XML Sitemap Generator for Google · support · 2026-02-05T06:10:00+00:00

mixedsentiment
highseverity
0.88relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 34 rows with source links

14.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
lilian9888 resolved
XML Sitemap Generator for Google <= 4.1.22 is vulnerable to Access Controls Severity: low (5.3) Exploited: No Fixed in: No fix yet Security risk: access controls. This vulnerability allows any unauthenticated user to perform actions that only an administrator should be allowed to do. This is very worrisome. Pretty sure our website was hacked last time this plugin had a security vulnerability. The latest release already addresses the issue, which is as reported, low severity. We have another patch with additional measures that the security groups have finally finished reviewing, so that security monitoring services will hopefully quickly acknowledge. I have been seeing this through Jetpack’s security scan as well. Jetpack says it’s due to WPScan sourcing the vulnerability via Patchstack. Patchstack still has it listed as “no official fix available,” and says that <= 4.1.22 are impacted. That’s probably why various security checks and scans are still screaming at everyone. https://vdp.patchstack.com/database/Wordpress/Plugin/google-sitemap-generator/vulnerability/wordpress-google-xml-sitemaps-plugin-4-1-21-broken-access-control-vulnerability @fredericktownes , thank you for continuing to work through this – as annoying as the security alerts have been, it sounds like you’re going through a significant hassle. You’re welcome! Thanks for your patience @sirstuey .

Comments

4 shown
deejmer 2026-02-05T18:34:00+00:00

This is very worrisome. Pretty sure our website was hacked last time this plugin had a security vulnerability.

Frederick Townes 2026-02-05T21:56:00+00:00

The latest release already addresses the issue, which is as reported, low severity. We have another patch with additional measures that the security groups have finally finished reviewing, so that security monitoring services will hopefully quickly acknowledge.

Stuey 2026-02-06T20:10:00+00:00

I have been seeing this through Jetpack’s security scan as well. Jetpack says it’s due to WPScan sourcing the vulnerability via Patchstack. Patchstack still has it listed as “no official fix available,” and says that <= 4.1.22 are impacted. That’s probably why various security checks and scans are still screaming at everyone. https://vdp.patchstack.com/database/Wordpress/Plugin/google-sitemap-generator/vulnerability/wordpress-google-xml-sitemaps-plugin-4-1-21-broken-access-control-vulnerability @fredericktownes , thank you for continuing to work through this – as annoying as the security alerts have been, it sounds like you’re going through a significant hassle.

Frederick Townes 2026-02-07T04:50:00+00:00

You’re welcome! Thanks for your patience @sirstuey .