CVE-2025-9512
The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modifications, making it possible for unauthenticated attackers to conduct Stored XSS attacks via post comments.
More information : https://wpscan.com/vulnerability/e45d9335-3665-4155-abdf-9eeea250f1ba/