Medium severity4.3NVD Advisory· Published Mar 25, 2024· Updated Jun 17, 2026
CVE-2024-1564
CVE-2024-1564
Description
The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <2.7.16
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/ecb1e36f-9c6e-4754-8878-03c97194644d/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.