Stored Cross-Site Scripting Vulnerability in WP SEO Structured Data Schema Plugin for WordPress
CVE-2025-4127

6.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
8 May 2025

Summary

The WP SEO Structured Data Schema plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the ā€˜Price Range’ parameter. This occurs due to insufficient input sanitization and output escaping, enabling attackers to inject arbitrary web scripts that will be executed whenever an administrator interacts with the plugin settings page. This vulnerability can lead to unauthorized access and actions, potentially compromising the security of the WordPress website.

Affected Version(s)

WP SEO Structured Data Schema * <= 2.7.11

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jƶrg SteinstrƤter
.