CVE-2026-82127
Received Received - Intake

Stored XSS in Schema & Structured Data for WP & AMP WordPress Plugin

Vulnerability report for CVE-2026-82127, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WPScan

Description

The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_amp the_schema_structured_data_for_wp_amp 1.67
wp_schema plugin to 1.67 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the Schema & Structured Data for WP & AMP WordPress plugin before version 1.67. It occurs because the plugin does not check user capabilities when saving certain fields and fails to properly escape them when displaying them. This allows users with the editor role or higher to inject malicious scripts.

Detection Guidance

Check the installed version of the Schema & Structured Data for WP & AMP plugin. If it is below 1.67, the system is vulnerable. Use WordPress admin dashboard or run: wp plugin list --name='schema-structured-data-wp-amp' in WP-CLI.

Impact Analysis

An attacker with editor access could inject malicious scripts that execute when a higher-privileged user views the affected screen. This could lead to unauthorized actions, data theft, or further compromise of the WordPress site. The impact is limited to multisite installations where editors lack the unfiltered_html capability.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Stored XSS attacks can expose sensitive user data or allow attackers to manipulate site content, potentially resulting in regulatory penalties.

Mitigation Strategies

Update the Schema & Structured Data for WP & AMP plugin to version 1.67 or later immediately. Ensure multisite installations restrict editor roles appropriately to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82127. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart