Extension WordPress

Vulnérabilités Schema & Structured Data for WP & AMP

Cette page rassemble les failles publiées pour Schema & Structured Data for WP & AMP, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
0Critiques
11Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Schema & Structured Data for WP & AMP

11 fiches

CVE-2025-14069 Moyenne · 6,4
Schema & Structured Data for WP & AMP

Schema & Structured Data for WP & AMP <= 1.54 – Authenticated (Contributor+) Stored Cross-Site Scripting via User Custom Schema

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saswp_custom_schema_field' profile field in all versions up to, and including, 1.54 due to insufficient input sanitization and output…

Versions affectées

*-1.54

Correctif

1.54.1

Publication

22/01/2026

CVE-2025-11502 Moyenne · 6,4
Schema & Structured Data for WP & AMP

Schema & Structured Data for WP & AMP <= 1.51 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all versions up to, and including, 1.51 due to insufficient input sanitization and output…

Versions affectées

*-1.51

Correctif

1.52

Publication

31/10/2025

CVE-2024-5582 Moyenne · 6,4
Schema & Structured Data for WP & AMP

Schema & Structured Data for WP & AMP <= 1.33 – Authenticated (Contributor+) Stored Cross-Site Scripting via url Attribute

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the Q&A Block widget in all versions up to, and including, 1.33 due to…

Versions affectées

*-1.33

Correctif

1.34.1

Publication

16/07/2024

CVE-2024-3491 Moyenne · 6,4
Schema & Structured Data for WP & AMP

Schema & Structured Data for WP & AMP <= 1.29 – Authenticated (Contributor+) Stored Cross-Site Scripting via How To and FAQ Blocks

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "How To" and "FAQ" Blocks in all versions up to, and including, 1.29 due to insufficient input…

Versions affectées

*-1.29

Correctif

1.30

Publication

22/04/2024

CVE-2024-1288 Moyenne · 4,3
Schema & Structured Data for WP & AMP

Schema & Structured Data for WP & AMP <= 1.26 – Missing Authorization to reCaptcha Key Modification

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saswp_reviews_form_render' function in all versions up to, and including, 1.26. This…

Versions affectées

*-1.26

Correctif

1.27

Publication

19/02/2024

CVE-2024-22146 Moyenne · 5,4
Schema & Structured Data for WP & AMP

Schema & Structured Data for WP & AMP <= 1.25 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.25 due to insufficient input sanitization and output escaping…

Versions affectées

*-1.25

Correctif

1.26

Publication

12/01/2024

CVE-2023-51677 Moyenne · 6,4
Schema & Structured Data for WP & AMP

Schema & Structured Data for WP & AMP <= 1.23 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.23 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.23

Correctif

1.24

Publication

27/12/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités