Impact
The Schema & Structured Data for WP & AMP plugin allows a stored cross‑site scripting flaw, identified as CWE‑79, through the "saswp_custom_schema_field" profile field. The vulnerability arises from insufficient input sanitization and output escaping, permitting attackers who can add or edit this custom schema field to embed arbitrary scripts into a WordPress page. Once stored, these scripts execute automatically whenever any site visitor loads the affected page, potentially hijacking user sessions or delivering malware.
Affected Systems
The affected system is the Schema & Structured Data for WP & AMP plugin developed by magazine3, used in WordPress installations. All releases up to and including version 1.54 contain the flaw; any site still running 1.54 or earlier is at risk.
Risk and Exploitability
The CVSS score of 6.4 reflects a moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. Attacking requires authenticated Contributor-level or higher access to the WordPress admin interface; the attacker can inject the malicious payload, which then affects all site visitors who view the compromised page. The exploit path is simple for an attacker with the required role, but the overall risk is constrained by the low EPSS and the need for authorisation.
OpenCVE Enrichment