PatchSiren

Ashish Ajani CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Ashish Ajani CVE published 2026-04-08

CVE-2026-39654

A DOM-Based XSS vulnerability was found in the WP Simple HTML Sitemap plugin. This issue allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data theft. The vulnerability affects WP Simple HTML Sitemap versions from n/a through 3.8. Users should review their plugin versions and update as necessary.