Stored Cross-Site Scripting Vulnerability in Schema & Structured Data Plugin for WordPress
CVE-2025-11502
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 November 2025
What is CVE-2025-11502?
The Schema & Structured Data for WP & AMP plugin for WordPress contains a vulnerability that allows authenticated users with contributor-level access and higher to exploit the 'saswp_tiny_multiple_faq' shortcode. This vulnerability stems from inadequate input sanitization and output escaping on user-supplied attributes, enabling attackers to inject arbitrary scripts. When those affected pages are accessed by users, the injected scripts execute, jeopardizing site integrity and user security.
Affected Version(s)
Schema & Structured Data for WP & AMP * <= 1.51