Impact
The vulnerable version of the Schema & Structured Data for WP & AMP plugin fails to verify whether a post is password protected before including the post content in the structured data it generates. This oversight allows unauthenticated users to read the content of password‑protected posts through public JSON‑LD schema output, effectively exposing information that should be restricted. The flaw occurs on any page that renders the plugin’s structured data and does not depend on additional authentication or privileges.
Affected Systems
Affected systems are installations of the Schema & Structured Data for WP & AMP WordPress plugin older than version 1.66. No other products or version ranges are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score indicates a probability of exploitation below 1 %. The vulnerability is not listed in CISA KEV, so there is no evidence of active exploitation at this time. The likely attack vector is an unauthenticated HTTP request to a page that outputs the JSON‑LD schema; no credentials, elevated privileges, or special network conditions are required to obtain the exposed content.
OpenCVE Enrichment