Description
The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more than one public output route.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerable version of the Schema & Structured Data for WP & AMP plugin fails to verify whether a post is password protected before including the post content in the structured data it generates. This oversight allows unauthenticated users to read the content of password‑protected posts through public JSON‑LD schema output, effectively exposing information that should be restricted. The flaw occurs on any page that renders the plugin’s structured data and does not depend on additional authentication or privileges.

Affected Systems

Affected systems are installations of the Schema & Structured Data for WP & AMP WordPress plugin older than version 1.66. No other products or version ranges are listed as impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, and the EPSS score indicates a probability of exploitation below 1 %. The vulnerability is not listed in CISA KEV, so there is no evidence of active exploitation at this time. The likely attack vector is an unauthenticated HTTP request to a page that outputs the JSON‑LD schema; no credentials, elevated privileges, or special network conditions are required to obtain the exposed content.

Generated by OpenCVE AI on September 20, 2026 at 06:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Schema & Structured Data for WP & AMP to version 1.66 or later.
  • If an upgrade is not immediately feasible, temporarily disable the plugin or remove the JSON‑LD generation for password‑protected posts.
  • As a last resort, modify the plugin’s output template to skip content for password‑protected posts until an official patch is available.

Generated by OpenCVE AI on September 20, 2026 at 06:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more than one public output route.
Title Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:38:39.622Z

Reserved: 2026-08-28T07:01:48.230Z

Link: CVE-2026-82124

cve-icon Vulnrichment

Updated: 2026-09-17T12:20:20.071Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:33.167

Modified: 2026-09-17T13:16:48.653

Link: CVE-2026-82124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:15:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor