CVE-2024-22146: WordPress Schema & Structured Data for WP & AMP Plugin <= 1.25 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.25.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Schema & Structured Data for WP & AMPto a version that resolves this vulnerability.Fixed in 1.26
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22146?
CVE-2024-22146 is classified as a Stored Cross-site Scripting (XSS) vulnerability, which can allow attackers to execute malicious scripts in a user's browser.
How do I fix CVE-2024-22146?
To resolve CVE-2024-22146, update the Magazine3 Schema & Structured Data for WP & AMP plugin to a version beyond 1.25.
What versions are affected by CVE-2024-22146?
CVE-2024-22146 affects all versions of the Magazine3 Schema & Structured Data for WP & AMP plugin up to and including version 1.25.
Can CVE-2024-22146 lead to data compromise?
Yes, CVE-2024-22146 can lead to data compromise as attackers can leverage stored XSS to steal user credentials or sensitive information.
What specific component is impacted by CVE-2024-22146?
CVE-2024-22146 specifically impacts the Magazine3 Schema & Structured Data for WP & AMP plugin used in WordPress.