Stored Cross-Site Scripting Vulnerability in Structured Content Plugin for WordPress
CVE-2025-4608
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2025
What is CVE-2025-4608?
The Structured Content plugin for WordPress is prone to Stored Cross-Site Scripting (XSS) vulnerabilities due to inadequate input sanitization and output escaping in the 'sc_fs_local_business' shortcode. This flaw affects all plugin versions up to and including 1.6.4, allowing authenticated attackers with contributor-level access or higher to inject malicious scripts. These scripts may execute automatically when users access compromised pages, posing significant security risks to website visitors.
Affected Version(s)
Structured Content (JSON-LD) #wpsc * <= 1.6.4