VYPR

Schema & Structured Data for WP & AMP

by WordPress

CVEs (15)

  • CVE-2026-97291HigSep 30, 2026
    risk 0.50cvss 8.8epss —

    Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.

  • CVE-2024-5582MedJul 17, 2024
    risk 0.42cvss 6.4epss 0.00

    The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the Q&A Block widget in all versions up to, and including, 1.33 due to insufficient input sanitization and output escaping on user…

  • CVE-2024-1586MedFeb 29, 2024
    risk 0.42cvss 6.4epss 0.00

    The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom schema in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2025-9512MedOct 1, 2025
    risk 0.40cvss 6.1epss 0.00

    The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modifications, making it possible for unauthenticated attackers to conduct Stored XSS attacks via post comments.

  • CVE-2025-14069MedJan 23, 2026
    risk 0.35cvss 6.4epss 0.00

    The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saswp_custom_schema_field' profile field in all versions up to, and including, 1.54 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2025-11502MedNov 1, 2025
    risk 0.35cvss 6.4epss 0.00

    The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all versions up to, and including, 1.51 due to insufficient input sanitization and output escaping on user supplied…

  • CVE-2024-3491MedApr 23, 2024
    risk 0.35cvss 6.4epss 0.00

    The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "How To" and "FAQ" Blocks in all versions up to, and including, 1.29 due to insufficient input sanitization and output escaping on user supplied…

  • CVE-2023-51677MedFeb 1, 2024
    risk 0.35cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.23.

  • CVE-2024-22146MedJan 31, 2024
    risk 0.35cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.25.

  • CVE-2026-82125MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comments still awaiting moderation or marked…

  • CVE-2026-82124MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more…

  • CVE-2024-1288MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.00

    The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saswp_reviews_form_render' function in all versions up to, and including, 1.26. This makes it possible for authenticated…

  • CVE-2024-49683MedOct 24, 2024
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Schema & Structured Data for WP & AMP: from n/a through <= 1.3.5.

  • CVE-2026-82127LowSep 30, 2026
    risk 0.23cvss 3.5epss 0.00

    The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute…

  • CVE-2026-82126LowSep 16, 2026
    risk 0.18cvss 2.7epss 0.00

    The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the content of other users' draft, pending,…