← WordPress Vulnerabilities
WordPress security by component

Schema & Structured Data for WP & AMP

Schema & Structured Data for WP & AMP is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jun 10, 2026; the highest CVE/CNA score is 9.1.

Plugin slug: schema-structured-data-for-wp-amp

CVE-2026-9067: Schema & Structured Data for WP & AMP: A security weakness

Schema & Structured Data for WP & AMP is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 1.60.

PublishedJun 10, 2026
Known safe version1.60
Known source slugs: schema-&-structured-data-for-wp-&-amp, schema-structured-data-for-wp-amp
Safe version
Jun 10, 2026 CVE-2026-9067
Schema & Structured Data for WP & AMP: A security weakness
Schema & Structured Data for WP & AMP is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 1.60.
1.60
CVE9.1
NVDPending
Oct 01, 2025 CVE-2025-9512
Schema & Structured Data for WP & AMP: Cross-site scripting
Schema & Structured Data for WP & AMP is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Apr 23, 2024 CVE-2024-3491
Schema & Structured Data for WP & AMP: Cross-site scripting
Schema & Structured Data for WP & AMP is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Feb 29, 2024 CVE-2024-1586
Schema & Structured Data for WP & AMP: Cross-site scripting
Schema & Structured Data for WP & AMP is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 29, 2024 CVE-2024-1288
Schema & Structured Data for WP & AMP: A security weakness
Schema & Structured Data for WP & AMP is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending