Stored Cross-Site Scripting Vulnerability in WP SEO Structured Data Schema Plugin for WordPress
CVE-2025-4127
5.4MEDIUM
What is CVE-2025-4127?
The WP SEO Structured Data Schema plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the āPrice Rangeā parameter. This occurs due to insufficient input sanitization and output escaping, enabling attackers to inject arbitrary web scripts that will be executed whenever an administrator interacts with the plugin settings page. This vulnerability can lead to unauthorized access and actions, potentially compromising the security of the WordPress website.
Affected Version(s)
WP SEO Structured Data Schema * <= 2.7.11