Executive brief
The WP SEO Structured Data Schema plugin for WordPress, which helps websites manage search engine optimization data, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the '_kcseo_ative_tab' parameter within the KcSeoMetaData.php file. This vulnerability affects all versions up to and including 2.8.1. An authenticated attacker with Contributor-level permissions or higher can inject arbitrary web scripts into the database. These scripts are then executed in the security context of any user (including administrators) who views the compromised page. The attack requires network access but is mitigated by the requirement for authenticated contributor-level privileges.
Affected products
- WP SEO Structured Data Schema WP SEO Structured Data Schema Up to, and including, 2.8.1
Timeline
- 2026-05-12: disclosed: Initial publication of the CVE record.
- 2026-05-12: advisory: Wordfence published the vulnerability details.
References
- https://plugins.trac.wordpress.org/browser/wp-seo-structured-data-schema/tags/2.8.1/lib/classes/KcSeoMetaData.php
- https://plugins.trac.wordpress.org/browser/wp-seo-structured-data-schema/tags/2.8.1/lib/classes/KcSeoMetaData.php
- https://plugins.trac.wordpress.org/browser/wp-seo-structured-data-schema/trunk/lib/classes/KcSeoMetaData.php
- https://plugins.trac.wordpress.org/browser/wp-seo-structured-data-schema/trunk/lib/classes/KcSeoMetaData.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/315fbc93-5af3-4fe9-b97a-a09957e54c97?source=cve