Impact
The Schema & Structured Data for WP & AMP plugin contains a stored XSS flaw in the 'saswp_tiny_multiple_faq' shortcode that occurs when user‑supplied attributes are not properly sanitized or escaped. An attacker who can add or edit the shortcode can embed arbitrary JavaScript that will execute in the browsers of all users who view the affected page, potentially leading to credential theft, session hijacking, and other malicious actions. This weakness is catalogued as CWE‑79, a classic input validation flaw that can compromise confidentiality and integrity of site content.
Affected Systems
The vulnerability exists in all releases of the Schema & Structured Data for WP & AMP plugin by magazine3 up to and including version 1.51. Any WordPress site that has this plugin installed and allows contributor‑level users to insert or modify content is impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% signals that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw requires authenticated contributor‑level access, an attacker who gains such privileges could easily abuse the plugin. The attack vector is inferred to be web‑based, relying on the attacker’s ability to inject content through the plugin’s shortcode interface.
OpenCVE Enrichment