PLUGIN SECURITY

Is Schema And Structured Data For Wp safe?

Schema & Structured Data adds Google Rich Snippets markup according to Schema.org guidelines to structure your site for SEO.

What this plugin does

  • Slug: schema-and-structured-data-for-wp
  • Author: Magazine3
  • 100000+ active installs
  • 90/100 rating (252 reviews on wordpress.org)
  • 7804782 all-time downloads
  • On WordPress.org since 2018-08-06

amprich snippetsschemaseostructured data

Maintenance status

  • Latest known version: 1.63
  • Last updated: 2026-08-17 8:15am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 5.6.20+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

11 known CVEs on file for Schema And Structured Data For Wp.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-9067 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.60 Unrestricted Upload of File with Dangerous Type Unknown < 1.60 1.60 2026-06-10 ✓ fixed in latest
CVE-2025-14069 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.54.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.54.1 1.54.1 2026-01-22 ✓ fixed in latest
CVE-2025-11502 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.52 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.52 1.52 2025-10-31 ✓ fixed in latest
CVE-2024-49683 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.36 Missing Authorization Medium 5.3 < 1.36 1.36 2024-10-21 ✓ fixed in latest
CVE-2024-5582 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.34.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.34.1 1.34.1 2024-07-16 ✓ fixed in latest
CVE-2024-3491 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.30 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.30 1.30 2024-04-22 ✓ fixed in latest
CVE-2024-1288 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.27 Improper Access Control Medium 4.3 < 1.27 1.27 2024-02-19 ✓ fixed in latest
CVE-2024-1586 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.27 1.27 2024-02-19 ✓ fixed in latest
+ 5 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-22146 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.26 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 1.26 1.26 2024-01-12 ✓ fixed in latest
CVE-2023-51677 Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.24 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 1.24 1.24 2023-12-27 ✓ fixed in latest
Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.50 Medium 6.1 < 1.50 1.50 0000-00-00 ✓ fixed in latest
CVE-2024-22146 Schema & Structured Data for WP & AMP < 1.26 - Contributor+ Stored Cross-Site Scripting Unknown < 1.26 1.26 ✓ fixed in latest
CVE-2025-9512 Schema & Structured Data for WP & AMP < 1.50 - Unauthenticated Stored-XSS Unknown < 1.50 1.50 ✓ fixed in latest

How to fix it

Keep Schema And Structured Data For Wp updated — 1.63 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.