plugin

Schema App Structured Data For Schemaorg Vulnerabilities

8 known security issues reported for the Schema App Structured Data For Schemaorg WordPress plugin. Most recent disclosed Jan 2, 2025.

4 medium

Running Schema App Structured Data For Schemaorg on your site? Check whether your installed version is affected.

Scan your site free

Schema App Structured Data [schema-app-structured-data-for-schemaorg] < 1.22.4

unknown

[en] Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1.

Affected:
up to 1.22.4
Fixed in:
1.22.4
Disclosed:
Jan 2, 2025

CVE-2023-44258 on NVD →

Schema App Structured Data [schema-app-structured-data-for-schemaorg] < 2.2.5

unknown

[en] The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Dec 12, 2024

CVE-2024-11279 on NVD →

Schema App Structured Data <= 2.2.4 - Reflected Cross-Site Scripting

medium

The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 2.2.4
Fixed in:
2.2.5
Disclosed:
Dec 11, 2024

CVE-2024-11279 on NVD →

Schema App Structured Data [schema-app-structured-data-for-schemaorg] < 2.2.1

unknown

[en] The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the MarkUpdate function. This makes it possible for unauthenticated attackers to update and delete post metadata via a...

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Jun 14, 2024

CVE-2024-0892 on NVD →

Schema App Structured Data <= 2.2.0 - Cross-Site Request Forgery

medium

The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the MarkUpdate function. This makes it possible for unauthenticated attackers to update and delete post metadata via a forg...

CVSS:
4.3
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Jun 13, 2024

CVE-2024-0892 on NVD →

Schema App Structured Data [schema-app-structured-data-for-schemaorg] < 2.2.1

unknown

[en] The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.1.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update or delet...

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
May 24, 2024

CVE-2024-0893 on NVD →

Schema App Structured Data <= 2.2.0 - Missing Authorization

medium

The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the MarkupUpdate function in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update or delete pos...

CVSS:
4.3
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
May 23, 2024

CVE-2024-0893 on NVD →

Schema App Structured Data <= 1.22.3 - Missing Authorization via page_init

medium

The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the page_init function in versions up to, and including, 1.22.3. This makes it possible for unauthenticated attackers to delete the plugin's transients.

CVSS:
5.3
Affected:
up to 1.22.3
Fixed in:
1.22.4
Disclosed:
Sep 27, 2023

CVE-2023-44258 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database