Impact
The Schema & Structured Data for WP & AMP plugin, versions 1.46 through 1.65, fails to enforce proper authorization checks when a comment’s content is retrieved. Because the plugin does not verify that the comment belongs to the requesting user or that the comment has been approved, an unauthenticated user can request a comment ID and receive the body of comments that are still pending moderation or have been marked as spam. This flaw exposes private user‑generated content, compromising confidentiality for potentially sensitive discussion data.
Affected Systems
WordPress sites that have the Schema & Structured Data for WP & AMP plugin installed at any version from 1.46 through 1.65. This includes installations that did not apply the vendor‑issued patch included in version 1.66.
Risk and Exploitability
The vulnerability qualifies as an IDOR that can be exploited via a simple HTTP request containing a comment identifier. An attacker does not need privileged access or knowledge of user accounts. The CVSS score is 5.3, indicating moderate impact, and the EPSS score is less than 1 %, suggesting a low likelihood of widespread exploitation. The flaw is not currently listed in the CISA KEV catalog. However, because any pending or spammed comment can be read by an unauthenticated user, the vulnerability provides a clear data‑leak channel that could compromise privacy on affected WordPress sites.
OpenCVE Enrichment