Impact
The Schema & Structured Data for WP & AMP plugin fails to enforce permission checks when generating AI schema, allowing a user with contributor privileges or higher to request schema creation for posts they do not own. This misuse exposes the full content of other users’ draft, pending, private, or password‑protected posts, compromising confidentiality.
Affected Systems
WordPress plugin Schema & Structured Data for WP & AMP, versions 1.63 through 1.65, before the 1.66 release.
Risk and Exploitability
The vulnerability is triggered by an authenticated WordPress user with at least contributor capabilities, meaning it can be exercised by anyone who can access the plugin’s schema generation UI. No public exploits are known and the EPSS score is below 1 percent, indicating a low probability of exploitation. The issue is not listed in the CISA KEV catalog, but the confidentiality impact is severe if a capable attacker can generate schema for a private post. The lack of a CVSS score requires reliance on the descriptive impact; the potential to read non‑public content makes this a high‑impact threat for organizations with sensitive unpublished material.
OpenCVE Enrichment