CVE · Medium

CVE-2024-3491 — Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.30

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3491 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.30 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.30 1.30 2024-04-22

CVE-2024-3491

The Schema & Structured Data for WP & AMP plugin contains a stored cross-site scripting vulnerability in its "How To" and "FAQ" Blocks affecting versions up to 1.29, resulting from inadequate sanitization of user-supplied attributes and improper escaping of output. Attackers with contributor-level permissions or higher can inject malicious scripts into pages that execute when visitors view the compromised content. The vulnerability requires authentication but allows arbitrary JavaScript execution on affected pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.