Schema App Structured Data [schema-app-structured-data-for-schemaorg] < 1.22.4
unknown
[en] Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1.
- Affected:
- up to 1.22.4
- Fixed in:
- 1.22.4
- Disclosed:
- Jan 2, 2025
CVE-2023-44258 on NVD →
Schema App Structured Data [schema-app-structured-data-for-schemaorg] < 2.2.5
unknown
[en] The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Dec 12, 2024
CVE-2024-11279 on NVD →
Schema App Structured Data <= 2.2.4 - Reflected Cross-Site Scripting
medium
The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- CVSS:
- 6.1
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.5
- Disclosed:
- Dec 11, 2024
CVE-2024-11279 on NVD →
Schema App Structured Data [schema-app-structured-data-for-schemaorg] < 2.2.1
unknown
[en] The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the MarkUpdate function. This makes it possible for unauthenticated attackers to update and delete post metadata via a...
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Jun 14, 2024
CVE-2024-0892 on NVD →
Schema App Structured Data <= 2.2.0 - Cross-Site Request Forgery
medium
The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the MarkUpdate function. This makes it possible for unauthenticated attackers to update and delete post metadata via a forg...
- CVSS:
- 4.3
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- Jun 13, 2024
CVE-2024-0892 on NVD →
Schema App Structured Data [schema-app-structured-data-for-schemaorg] < 2.2.1
unknown
[en] The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.1.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update or delet...
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- May 24, 2024
CVE-2024-0893 on NVD →
Schema App Structured Data <= 2.2.0 - Missing Authorization
medium
The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update or delete pos...
- CVSS:
- 4.3
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- May 23, 2024
CVE-2024-0893 on NVD →
Schema App Structured Data <= 1.22.3 - Missing Authorization via page_init
medium
The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the page_init function in versions up to, and including, 1.22.3. This makes it possible for unauthenticated attackers to delete the plugin's transients.
- CVSS:
- 5.3
- Affected:
- up to 1.22.3
- Fixed in:
- 1.22.4
- Disclosed:
- Sep 27, 2023
CVE-2023-44258 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database