PT-2026-103026 · WordPress · Schema & Structured Data For Wp & Amp
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Schema & Structured Data for WP & AMP versions prior to 1.67
Description
On multisite installations, the plugin fails to perform capability checks when saving certain fields and does not escape them during output. This allows users with the editor role or higher, who lack the
unfiltered html capability, to inject arbitrary web scripts. These scripts execute when a user with higher privileges views the affected screen.Recommendations
Update Schema & Structured Data for WP & AMP to version 1.67 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Schema & Structured Data For Wp & Amp