Wpsc-plugin
Wpsc-plugin Structured Content: vulnerabilidades y CVE
Wpsc-plugin Structured Content tiene 9 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-57763 | Media (6.5) | 0.22% | — | 2 jul 2026 | Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions. |
| CVE-2025-4608 | Media (6.4) | 0.42% | — | 24 jul 2025 | The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization… |
| CVE-2025-30918 | Media (6.5) | 0.29% | — | 27 mar 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme Structured Content structured-content allows Stored XSS.This issue affects Structured Content: from n/a… |
| CVE-2025-0512 | Media (5.4) | 0.28% | — | 4 mar 2025 | The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and including, 6.4.5 due to insufficient… |
| CVE-2024-43307 | Media (6.5) | 0.26% | — | 18 ago 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from… |
| CVE-2024-24839 | Media (5.4) | 0.32% | — | 5 feb 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc allows Stored XSS.This issue affects Structured… |
| CVE-2023-49819 | Crítica (9.8) | 0.75% | — | 19 dic 2023 | Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3. |
| CVE-2023-49820 | Media (5.4) | 0.39% | — | 14 dic 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc allows Stored XSS.This issue affects Structured… |
| CVE-2022-4715 | Media (5.4) | 0.47% | — | 23 ene 2023 | The Structured Content WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to… |