CVE-2025-3414
BaseFortify
Publication date: 2025-08-14
Last updated on: 2025-08-14
Assigner: WPScan
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wpscan | structured_content | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Structured Content (JSON-LD) #wpsc WordPress plugin before version 1.7.0. It occurs because the plugin does not properly validate and escape some of its block options before outputting them on a page or post where the block is embedded. This flaw allows users with the contributor role and above to perform Stored Cross-Site Scripting (XSS) attacks.
How can this vulnerability impact me? :
The vulnerability can allow users with contributor or higher roles to inject malicious scripts into pages or posts. These scripts are stored and executed when other users view the affected content, potentially leading to unauthorized actions, data theft, session hijacking, or defacement of the website.