CVE-2025-14069
- EPSS 0.01%
- Veröffentlicht 23.01.2026 05:29:51
- Zuletzt bearbeitet 26.01.2026 15:03:51
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saswp_custom_schema_field' profile field in all versions up to, and including, 1.54 due to insufficient input sanitization and output...
CVE-2025-11502
- EPSS 0.05%
- Veröffentlicht 01.11.2025 05:40:24
- Zuletzt bearbeitet 04.11.2025 15:41:31
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all versions up to, and including, 1.51 due to insufficient input sanitization and out...
CVE-2024-5582
- EPSS 0.43%
- Veröffentlicht 17.07.2024 08:15:02
- Zuletzt bearbeitet 21.11.2024 09:47:58
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the Q&A Block widget in all versions up to, and including, 1.33 due to insufficient input sanitization...
CVE-2024-3491
- EPSS 0.11%
- Veröffentlicht 23.04.2024 11:15:45
- Zuletzt bearbeitet 21.11.2024 09:29:43
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "How To" and "FAQ" Blocks in all versions up to, and including, 1.29 due to insufficient input sanitization and output escapi...
CVE-2024-1586
- EPSS 0.18%
- Veröffentlicht 29.02.2024 01:43:52
- Zuletzt bearbeitet 04.03.2025 12:25:17
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom schema in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping. This makes it pos...
CVE-2024-1288
- EPSS 0.13%
- Veröffentlicht 29.02.2024 01:43:46
- Zuletzt bearbeitet 11.03.2025 16:49:51
The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'saswp_reviews_form_render' function in all versions up to, and including, 1.26. This makes it ...
CVE-2024-22146
- EPSS 0.08%
- Veröffentlicht 31.01.2024 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:55:40
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.25.