CVE-2025-9512
BaseFortify
Publication date: 2025-10-01
Last updated on: 2025-10-02
Assigner: WPScan
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpress | plugin_schema_and_structured_data_for_wp_and_amp | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Schema & Structured Data for WP & AMP WordPress plugin before version 1.50. It improperly handles modifications to HTML tag attributes, which allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) attacks through post comments.
How can this vulnerability impact me? :
An attacker can exploit this vulnerability to inject malicious scripts into post comments, which are then stored and executed in the browsers of users who view those comments. This can lead to theft of user data, session hijacking, or other malicious actions performed on behalf of the victim.