Impact
The vulnerable version of the Schema & Structured Data for WP & AMP plugin fails to verify whether a post is password JSON‑LD schema that it outputs. As a result, anyone who can view the page can also retrieve the text of a protected post through one of the plugin’s public JSON‑LD output routes.
Affected Systems
Affected systems are installations of the Schema & Structured Data for WP & AMP WordPress plugin older than version 1.66. No other products or version ranges are listed.
Risk and Exploitability
The EPSS score indicates a probability of exploitation below 1 % and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the flaw allows unauthenticated users to read protected content, which is a direct information‑disclosure risk. Attackers only need HTTP access to a page that renders the JSON‑LD schema; no credentials or additional primitives are required.
OpenCVE Enrichment