Stored Cross-Site Scripting Vulnerability in WP SEO Structured Data Schema Plugin for WordPress
CVE-2025-4127
6.4MEDIUM
Summary
The WP SEO Structured Data Schema plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the āPrice Rangeā parameter. This occurs due to insufficient input sanitization and output escaping, enabling attackers to inject arbitrary web scripts that will be executed whenever an administrator interacts with the plugin settings page. This vulnerability can lead to unauthorized access and actions, potentially compromising the security of the WordPress website.
Affected Version(s)
WP SEO Structured Data Schema * <= 2.7.11
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jƶrg SteinstrƤter