CVE Database /
CVE-2024-1288
CVE · Medium
CVE-2024-1288 — Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.27
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-1288
|
Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.27 |
Improper Access Control |
Medium
4.3
|
< 1.27
|
1.27 |
2024-02-19 |
—
|
CVE-2024-1288
The WordPress Schema & Structured Data for WP & AMP plugin versions before 1.27 contain a broken access control flaw that permits unauthorized users to perform actions restricted to higher privilege levels due to missing authorization, authentication, or nonce verification. Researcher Ngô Thiên An identified and disclosed this vulnerability, which was patched in version 1.27 and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings