CVE Database /
CVE-2018-20977
CVE · Medium
CVE-2018-20977 — Schema – All In One Schema Rich Snippets [all-in-one-schemaorg-rich-snippets] < 1.5.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2018-20977
|
Schema – All In One Schema Rich Snippets [all-in-one-schemaorg-rich-snippets] < 1.5.0 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 1.5.0
|
1.5.0 |
2017-04-04 |
—
|
CVE-2018-20977
The Schema – All In One Schema Rich Snippets WordPress plugin contained an authenticated cross-site scripting flaw affecting versions prior to 1.5.0. This vulnerability allowed attackers with authenticated access to inject malicious scripts that could be executed within the WordPress environment.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings