PT-2025-20364 · WordPress · Wp Seo Structured Data Schema

Jörg Steinsträter

·

Published

2025-05-08

·

Updated

2025-06-05

·

CVE-2025-4127

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP SEO Structured Data Schema plugin for WordPress versions up to and including 2.7.11
Description The issue is related to Stored Cross-Site Scripting via the Price Range parameter, which is caused by insufficient input sanitization and output escaping. This allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts that execute when an administrator accesses the plugin settings page.
Recommendations For WP SEO Structured Data Schema plugin for WordPress versions up to and including 2.7.11, update to a version higher than 2.7.11 to resolve the issue. As a temporary workaround, consider restricting access to the plugin settings page to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-4127

Affected Products

Wp Seo Structured Data Schema