Impact
The Structured Content plugin up to version 1.7.0 contains a contributor cross‑site scripting flaw that allows arbitrary JavaScript to be executed when a user views content that has been submitted by a contributor. This flaw arises from insufficient filtering of user‑supplied content.
Affected Systems
WordPress sites that have the Structured Content plugin from Gordon Böhme installed at version 1.7.0 or earlier are affected. Only sites running a newer release are immune.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity and the EPSS score of less than 1 % suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is the submission of malicious content by a user with contributor privileges, which is then rendered in the browser without proper sanitization.
OpenCVE Enrichment