Magazine3 develops a suite of WordPress plugins focused on performance optimization, structured data markup, and content enhancement, serving a modestly represented but more prominent than typical segment of the WordPress ecosystem. Its vulnerability profile centers on web-application input-handling and access-control weaknesses—including cross-site scripting, missing authorization, improper access control, open redirects, and unrestricted file uploads—that recur across products such as PWA for WordPress, AMP for WordPress, and Core Web Vitals & PageSpeed Booster. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Magazine3 over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4354HIGH The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader function in versions up to, and | Jun 7, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-47318HIGH Missing Authorization vulnerability in Magazine3 PWA for WP & AMP pwa-for-wp.This issue affects PWA for WP & AMP: from n/a through <= 1.7.72. | Nov 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-11502MEDIUM The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all versions up | Nov 1, 2025 | 6.4 | 23 | NO | NO |
CVE-2025-14069MEDIUM The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saswp_custom_schema_field' profile field in all versions up to, | Jan 23, 2026 | 6.4 | 22 | NO | NO |
CVE-2025-13738MEDIUM The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` shortcode in all versions up to, and including, 2.0.78 due to | Feb 19, 2026 | 6.4 | 21 | NO | NO |
CVE-2023-35883MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magazine3 Core Web Vitals & PageSpeed Booster.This issue affects Core Web Vitals & PageSpeed Booster: from n/a | Dec 19, 2023 | 6.1 | 20 | NO | NO |
CVE-2018-20838MEDIUM ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS. | May 13, 2019 | 5.4 | 20 | NO | NO |
CVE-2024-7082MEDIUM The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site S | Aug 6, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-3491MEDIUM The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "How To" and "FAQ" Blocks in all versions up to, and in | Apr 23, 2024 | 6.4 | 19 | NO | NO |
CVE-2023-48321MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmed Kaludi, Mohammed Kaludi AMP for WP – Accelerated Mobile Pages allows Sto | Nov 30, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Magazine3.
Media articles that mention a CVE ID that affects a product developed by Magazine3 — matched by CVE ID, not by vendor name.