PT-2024-15898 · WordPress · Schema App Structured Data

Francesco Carlucci

·

Published

2024-05-24

·

Updated

2025-04-04

·

CVE-2024-0893

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Schema App Structured Data plugin for WordPress versions prior to 2.1.1
Description The issue allows authenticated attackers with subscriber access or higher to update or delete post metadata due to a missing capability check on the MarkupUpdate function.
Recommendations For versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-0893

Affected Products

Schema App Structured Data