PT-2025-33125 · WordPress · Structured Content (Json-Ld) #Wpsc

Krugov Aryom

·

Published

2025-08-14

·

Updated

2025-08-14

·

CVE-2025-3414

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Structured Content (JSON-LD) #wpsc WordPress plugin versions prior to 1.7.0
Description: The Structured Content (JSON-LD) #wpsc WordPress plugin does not validate and escape certain block options before displaying them within a page or post, potentially allowing users with contributor-level access or higher to execute Stored Cross-Site Scripting attacks.
Recommendations: Update to Structured Content (JSON-LD) #wpsc WordPress plugin version 1.7.0 or later.

Exploit

Fix

Related Identifiers

CVE-2025-3414

Affected Products

Structured Content (Json-Ld) #Wpsc