WordPress Plugin Vulnerabilities

Schema & Structured Data for WP & AMP < 1.36 - Unauthenticated Sensitive Information Exposure

Description

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.35 via uploads stored in an unsafe directory. This makes it possible for unauthenticated attackers to extract potentially sensitive data from uploads.

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Joshua Chan
Verified
No

Timeline

Publicly Published
2024-10-21 (about 1 year ago)
Added
2024-10-30 (about 1 year ago)
Last Updated
2024-10-30 (about 1 year ago)

Other