Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-82127— Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields

Quick assessment

Affected
Unknown Schema & Structured Data for WP & AMP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 “Schema & Structured Data for WP & AMP” 在 1.67 版本之前,在保存其多个字段时未执行权限检查,且在输出这些字段时也未进行转义处理。这使得拥有“编辑者”(editor)角色或更高权限的用户能够注入任意 Web 脚本,当具有更高权限的用户查看受影响的管理界面时,这些脚本将被执行。该漏洞仅在多站点(multisite)安装环境中可被利用,因为在多站点环境下,“编辑者”角色通常不具备 权限。

AI Predicted 6.4 Difficulty: Moderate EPSS 0.14% · P3

Possible ATT&CK Techniques 1 AI

T1059.007 · JavaScript

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Schema & Structured Data for WP & AMP < 1.67 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82127

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields
Source: CVE Program / CVE List V5
Vulnerability Description
The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Schema & Structured Data for WP & AMP 0 ~ 1.67 -

II. Public POCs for CVE-2026-82127

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82127

请登录查看更多情报信息。

Other References for CVE-2026-82127 (1)

Same Patch Batch · Unknown · 2026-09-30 · 28 CVEs total

CVE-2026-87777 Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attrib
CVE-2026-100143 FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email
CVE-2026-75824 WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disab
CVE-2026-75823 WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration R
CVE-2026-80333 Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview R
CVE-2026-83560 New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass
CVE-2026-75873 Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload
CVE-2026-86789 Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Dis
CVE-2026-85001 EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribut
CVE-2026-85415 Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL
CVE-2026-85576 All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings U
CVE-2026-85573 All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SV
CVE-2026-88791 Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules
CVE-2026-88797 Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation
CVE-2026-94274 YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API
CVE-2026-89193 Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTM
CVE-2026-89190 Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax
CVE-2026-90953 Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics
CVE-2026-91072 EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path
CVE-2026-91051 EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings'

Showing top 20 of 28 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-82127

No comments yet


Leave a comment