Impact
The Schema & Structured Data for WP & AMP plugin, versions 1.46 through 1.65, fails to verify that a comment belongs to the requesting user or that it has been approved before returning its content. Because this check is missing, an unauthenticated user can obtain the text of comments that are still pending moderation or that have been marked as spam. The result is a direct exposure of private or unreviewed user‑generated content, which could reveal sensitive information or compromise user privacy.
Affected Systems
WordPress sites that have the Schema & Structured Data for WP & AMP plugin installed at any version from 1.46 up to and including 1.65. The vendor is listed in the CVE as “Unknown:Schema & Structured Data for is provided beyond that plugin.
Risk and Exploitability
The vulnerability is a classic IDOR (in‑direct ownership disclosure) that can be triggered by an unauthenticated HTTP request containing a comment identifier. It does not require privileged access, existing knowledge of a user’s comment ID, or server‑side configuration changes. The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not yet included in the CISA KEV catalog. Nonetheless, because the flaw allows direct reading of any pending or spammed comment, it grants attackers a visible data‑leak channel for many sites that rely on the plugin.
OpenCVE Enrichment