WordPress · Schema & Structured Data For Wp & Amp · CVE-2026-82127
**Name of the Vulnerable Software and Affected Versions**
Schema & Structured Data for WP & AMP versions prior to 1.67
**Description**
On multisite installations, the plugin fails to perform capability checks when saving certain fields and does not escape them during output. This allows users with the editor role or higher, who lack the `unfiltered html` capability, to inject arbitrary web scripts. These scripts execute when a user with higher privileges views the affected screen.
**Recommendations**
Update Schema & Structured Data for WP & AMP to version 1.67 or later.