Description
The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comments still awaiting moderation or marked as spam.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The Schema & Structured Data for WP & AMP plugin, versions 1.46 through 1.65, fails to enforce proper authorization checks when a comment’s content is retrieved. Because the plugin does not verify that the comment belongs to the requesting user or that the comment has been approved, an unauthenticated user can request a comment ID and receive the body of comments that are still pending moderation or have been marked as spam. This flaw exposes private user‑generated content, compromising confidentiality for potentially sensitive discussion data.

Affected Systems

WordPress sites that have the Schema & Structured Data for WP & AMP plugin installed at any version from 1.46 through 1.65. This includes installations that did not apply the vendor‑issued patch included in version 1.66.

Risk and Exploitability

The vulnerability qualifies as an IDOR that can be exploited via a simple HTTP request containing a comment identifier. An attacker does not need privileged access or knowledge of user accounts. The CVSS score is 5.3, indicating moderate impact, and the EPSS score is less than 1 %, suggesting a low likelihood of widespread exploitation. The flaw is not currently listed in the CISA KEV catalog. However, because any pending or spammed comment can be read by an unauthenticated user, the vulnerability provides a clear data‑leak channel that could compromise privacy on affected WordPress sites.

Generated by OpenCVE AI on September 20, 2026 at 05:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Schema & Structured Data for WP & AMP plugin to version 1.66 or newer, which adds the missing ownership and moderation checks.
  • If an upgrade cannot be performed immediately, disable unauthenticated comment previewing by adjusting the plugin’s settings or by blocking comment‑ID URLs for unauthenticated requests with a firewall rule.
  • Log and monitor access to comment content endpoints, block repeated suspicious requests, and report incidents to your security team.

Generated by OpenCVE AI on September 20, 2026 at 05:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-639

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comments still awaiting moderation or marked as spam.
Title Schema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Public Comment Content Disclosure via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:38:24.648Z

Reserved: 2026-08-28T07:01:49.985Z

Link: CVE-2026-82125

cve-icon Vulnrichment

Updated: 2026-09-17T12:20:06.550Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:33.270

Modified: 2026-09-17T13:16:48.837

Link: CVE-2026-82125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:15:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key