CVE-2024-5582

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the Q&A Block widget in all versions up to, and including, 1.33 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Schema &amp; Structured Data for WP &amp; AMP adds Google Rich Snippets markup according to Schema.org guidelines to structure your site for SEO. (AMP Compatible)</p> <p><a href="https://structured-data-for-wp.com/" rel="nofollow ugc">Home</a> | <a href="https://structured-data-for-wp.com/contact-us/" rel="nofollow ugc">Help &amp; Tech Support</a> | <a href="https://structured-data-for-wp.com/docs/" rel="nofollow ugc">Documentation</a> | <a href="https://structured-data-for-wp.com/pricing/" rel="nofollow ugc">Pro version Features</a></p> <h3>Features</h3> <ul> <li><strong>Schema Types</strong>: Currently, We have more than 35 schema types such as Blog Posting, News article, Local Business, Web page, Article, Recipe, Product, and Video Object <a href="https://structured-data-for-wp.com/docs/article/how-many-schema-types-do-we-support/" rel="nofollow ugc">view all</a>. We are going to add all the schema types in the future. You can request the one you want and we will add it for you! </li> <li><strong>Schema Templates</strong>: Create a predefined set of schema markups and use them in main schema types <a href="https://structured-data-for-wp.com/docs/article/how-to-use-schema-templates-in-schema-structured-data-for-wp-amp/" rel="nofollow ugc">learn more</a>. </li> <li><strong>Conditional Display Fields</strong>: Meaning you include or exclude any posts, pages, post types, taxonomies and more! </li> <li><strong>Knowlegde Base Support</strong>: Recognize the content based on the organization or a person via data type option.</li> <li><strong>Full AMP Compatiblity</strong>: Supports the AMP for WP and AMP by Automattic plugins. </li> <li><strong>Advanced Settings</strong>: Play with output of schema markup using these options (Defragment, Add in Footer, Pretty Print, MicroData CleanUp etc.)</li> <li><strong>Migration</strong>: Import the data from other schema plugins such as (SEO Pressor, WP SEO Schema, Schema Plugin etc )</li> <li><strong>Compatibility</strong>: Generate the schema markup for the plugins. We have provided schema support for them. Few of them are &#8211; kk Star Ratings, WP-PostRatings, bbPress, Easy Liveblogs, wpForo, RealtyPress Premium, Discout Rules, WP Job Board Pro, EventPrime, Joli FAQ SEO</li> <li><strong>Google Review</strong>: Display your business google reviews and its schema markup on your website.</li> <li><strong>[Premium]</strong> Reviews ( <a href="https://structured-data-for-wp.com/reviews-for-schema" rel="nofollow ugc">Fetch</a> reviews from 75+ platforms ).</li> <li><strong>[Premium]</strong> Priority Support. <a href="https://structured-data-for-wp.com/priority-support/" rel="nofollow ugc">Get it</a> We get more than 100 technical queries a day but the Priority support plan will help you skip that and get the help from a dedicated team.</li> <li><strong>Review Module</strong>: Create your own review rating box with pros and cons and its schema markup</li> <li><strong>Schema Type Blocks in Gutenberg</strong>: Create your own content with the blocks and json schema markup will be added automatically</li> <li><strong>Unlimited Custom Post Types</strong>: You can control to represent the Rich Snippets data in the google search console using unlimited custom post types.</li> <li><strong>Easy to use</strong> with Minimal Settings</li> <li><strong>Archive Page Listing</strong> Support </li> <li><strong>JSON-LD</strong> Format</li> <li><strong>Easy to use</strong> Setup Wizard</li> <li><strong>Breadcrumbs</strong> Listing Support</li> <li><strong>Comments</strong> Post comments Support</li> <li><strong>Constant Development &amp; New Features</strong>: We’ll be releasing the constant updates along with the more handy features as soon as we get the feedback from the users.</li> </ul> <h3>Supported Schema Types</h3> <ul> <li>Apartment</li> <li>House</li> <li>SingleFamilyResidence</li> <li>Article</li> <li>Blogposting</li> <li>Book</li> <li>Course</li> <li>DiscussionForumPosting,</li> <li>DataFeed</li> <li>HowTo</li> <li>NewsArticle</li> <li>QAPage</li> <li>Review</li> <li>Recipe</li> <li>TVSeries</li> <li>SoftwareApplication</li> <li>MobileApplication</li> <li>SpecialAnnouncement (Related to Coronavirus)</li> <li>TechArticle</li> <li>WebPage</li> <li>Event</li> <li>VideoGame</li> <li>JobPosting</li> <li>Service</li> <li>Trip</li> <li>AudioObject</li> <li>VideoObject</li> <li>MedicalCondition</li> <li>MusicPlaylist</li> <li>MusicAlbum</li> <li>LocalBusiness with all the sub categories</li> <li>Product</li> <li>ProductGroup</li> <li>TouristAttraction</li> <li>TouristDestination</li> <li>LandmarksOrHistoricalBuildings</li> <li>HinduTemple</li> <li>Church</li> <li>Mosque</li> <li>Person</li> <li>LiveBlogPosting</li> <li>ImageGallery</li> <li>MediaGallery</li> <li>VacationalRental</li> <li>CriticReview</li> <li>ProfilePage</li> <li>Game</li> <li>Certification</li> <li>Guide</li> <li><a href="https://structured-data-for-wp.com/docs/article/how-many-schema-types-do-we-support/" rel="nofollow ugc">View All</a></li> </ul> <h3>Extensions</h3> <p>Some useful extensions to extend Schema &amp; Structured Data for WP &amp; AMP features</p> <ol> <li><a href="https://structured-data-for-wp.com/extensions/woocommerce-compatibility-for-schema/" rel="nofollow ugc">Woocommerce Compatibility For Schema</a> </li> <li><a href="https://structured-data-for-wp.com/wpml-schema-compatibility/" rel="nofollow ugc">WPML Schema Compatibility</a> </li> <li><a href="https://structured-data-for-wp.com/polylang-compatibility-for-saswp" rel="nofollow ugc">Polylang Compatibility For SASWP</a></li> <li><a href="https://structured-data-for-wp.com/faq-schema-compatibility/" rel="nofollow ugc">FAQ Schema Compatibility</a></li> <li><a href="https://structured-data-for-wp.com/event-schema/" rel="nofollow ugc">Event Schema</a></li> <li><a href="https://structured-data-for-wp.com/services/google-news-schema-setup/" rel="nofollow ugc">Google News Schema Setup</a></li> <li><a href="https://structured-data-for-wp.com/reviews-for-schema" rel="nofollow ugc">Show Business Reviews in Google SERP!</a></li> <li><a href="https://structured-data-for-wp.com/classifieds-plugin-compatibility/" rel="nofollow ugc">Classifieds Plugin Compatibility</a></li> <li><a href="https://structured-data-for-wp.com/1-click-indexing-api-integration/" rel="nofollow ugc">1-Click Indexing API Integration</a></li> <li><a href="https://structured-data-for-wp.com/jobposting-schema-compatibility/" rel="nofollow ugc">JobPosting Schema Compatibility</a></li> <li><a href="https://structured-data-for-wp.com/recipe-schema/" rel="nofollow ugc">Recipe Schema</a></li> <li><a href="https://structured-data-for-wp.com/course-schema/" rel="nofollow ugc">Course Schema</a></li> <li><a href="https://structured-data-for-wp.com/extensions/real-estate-schema/" rel="nofollow ugc">Real Estate Schema</a></li> <li><a href="https://structured-data-for-wp.com/qanda-schema-for-saswp/" rel="nofollow ugc">Q&amp;A Schema Compatibility</a></li> <li><a href="https://structured-data-for-wp.com/extensions/woocommerce-compatibility-for-schema/" rel="nofollow ugc">WooCommerce Compatibility for Schema</a></li> </ol> <h3>Support</h3> <p>We try our best to provide support on WordPress.org forums. However, We have a special <a href="https://structured-data-for-wp.com/contact-us/" rel="nofollow ugc">team support</a> where you can ask us questions and get help. Delivering a good user experience means a lot to us and so we try our best to reply each and every question that gets asked.</p> <h3>Bug Reports</h3> <p>Bug reports for Schema &amp; Structured Data for WP &amp; AMP are <a href="https://github.com/ahmedkaludi/schema-and-structured-data-for-wp/issues" rel="nofollow ugc">welcomed on GitHub</a>. Please note GitHub is not a support forum, and issues that aren&#8217;t properly qualified as bugs will be closed.</p> <h3>Credits</h3> <ul> <li>Select2 used https://github.com/select2/select2 &#8211; License URI: https://github.com/select2/select2/blob/develop/LICENSE.md,</li> <li>Merlin WP used https://github.com/richtabor/MerlinWP &#8211; License URI: https://github.com/richtabor/MerlinWP/blob/master/LICENSE,</li> <li>jquery-timepicker used https://github.com/jonthornton/jquery-timepicker</li> <li>Rate Yo! used https://github.com/prrashi/rateYo &#8211; License URI: https://github.com/prrashi/rateYo/commit/f3812fe96c38b08627d209795176053550fb1427</li> <li>Aqua Resizer used http://aquagraphite.com &#8211; License URI: WTFPL &#8211; http://sam.zoy.org/wtfpl/</li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
7.49M