The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range’ parameter in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts that will execute whenever an administrator accesses the plugin settings page.
History

Wed, 04 Jun 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Wpsemplugins
Wpsemplugins wp Seo Structured Data Schema
CPEs cpe:2.3:a:wpsemplugins:wp_seo_structured_data_schema:*:*:*:*:free:wordpress:*:*
Vendors & Products Wpsemplugins
Wpsemplugins wp Seo Structured Data Schema

Thu, 08 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 May 2025 07:00:00 +0000

Type Values Removed Values Added
Description The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range’ parameter in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts that will execute whenever an administrator accesses the plugin settings page.
Title WP SEO Structured Data Schema <= 2.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin Settings
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-05-08T06:39:50.774Z

Updated: 2025-05-08T14:09:41.638Z

Reserved: 2025-04-30T07:43:07.570Z

Link: CVE-2025-4127

cve-icon Vulnrichment

Updated: 2025-05-08T14:09:36.617Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-08T07:15:54.727

Modified: 2025-06-04T22:46:00.467

Link: CVE-2025-4127

cve-icon Redhat

No data.