Extension WordPress
Vulnérabilités Schema & Structured Data for WP & AMP
Cette page rassemble les failles publiées pour Schema & Structured Data for WP & AMP, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Schema & Structured Data for WP & AMP
11 fiches
Schema & Structured Data for WP & AMP < 1.60 – Unauthenticated Arbitrary Media Upload
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to arbitrary file uploads due to missing access control in all versions up to 1.60 (exclusive). This makes it possible for unauthenticated attackers to…
[*, 1.60)
1.60
11/06/2026
Schema & Structured Data for WP & AMP <= 1.54 – Authenticated (Contributor+) Stored Cross-Site Scripting via User Custom Schema
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saswp_custom_schema_field' profile field in all versions up to, and including, 1.54 due to insufficient input sanitization and output…
*-1.54
1.54.1
22/01/2026
Schema & Structured Data for WP & AMP <= 1.51 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all versions up to, and including, 1.51 due to insufficient input sanitization and output…
*-1.51
1.52
31/10/2025
Schema & Structured Data for WP & AMP <= 1.49 – Unauthenticated Stored Cross-Site Scripting
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post comments in all versions up to, and including, 1.49 due to insufficient input sanitization and output escaping. This…
*-1.49
1.50
10/09/2025
Schema & Structured Data for WP & AMP <= 1.35 – Unauthenticated Sensitive Information Exposure
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.35 via uploads stored in an unsafe directory. This makes it possible for…
*-1.35
1.36
21/10/2024
Schema & Structured Data for WP & AMP <= 1.33 – Authenticated (Contributor+) Stored Cross-Site Scripting via url Attribute
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the Q&A Block widget in all versions up to, and including, 1.33 due to…
*-1.33
1.34.1
16/07/2024
Schema & Structured Data for WP & AMP <= 1.29 – Authenticated (Contributor+) Stored Cross-Site Scripting via How To and FAQ Blocks
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "How To" and "FAQ" Blocks in all versions up to, and including, 1.29 due to insufficient input…
*-1.29
1.30
22/04/2024
Schema & Structured Data for WP & AMP <= 1.26 – Missing Authorization to reCaptcha Key Modification
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saswp_reviews_form_render' function in all versions up to, and including, 1.26. This…
*-1.26
1.27
19/02/2024
Schema & Structured Data for WP & AMP <= 1.26 – Authenticated (Custom) Stored Cross-Site Scripting
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom schema in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping.…
*-1.26
1.27
19/02/2024
Schema & Structured Data for WP & AMP <= 1.25 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.25 due to insufficient input sanitization and output escaping…
*-1.25
1.26
12/01/2024
Schema & Structured Data for WP & AMP <= 1.23 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.23 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.23
1.24
27/12/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.