Description
The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is due to the plugin registering the /wordlift/v1/jsonld/ routes (jsonld/{id}, jsonld/http/{item_id}, jsonld/post-meta/{meta_key}, jsonld/meta/{meta_key}, and jsonld/{post_type}/{post_name}) with a permission_callback of '__return_true' and the downstream converter retrieving the post via get_post() without verifying the post status or the requesting user's capabilities. This makes it possible for unauthenticated attackers to read the title, content/description, author, publication and modification dates, word count, comment count, and other metadata of private, draft, and pending posts by enumerating post IDs, bypassing WordPress core access controls.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information exposure (confidentiality breach)
Action: Update Plugin
AI Analysis

Impact

The WordLift – AI powered SEO – Schema plugin for WordPress contains a flaw in its JSON‑LD REST API endpoints. The plugin registers routes such as /wordlift/v1/jsonld/... with a permission callback that always returns true, and the downstream code retrieves posts via get_post() without checking the post status or the requesting user’s capabilities. As a result, unauthenticated users can enumerate post IDs and read the title, content, author, publication and modification dates, word count, comment count, and other metadata for private, draft, and pending posts, bypassing WordPress core access controls. This represents a clear confidentiality breach consistent with CWE‑200.

Affected Systems

Any WordPress installation using WordLift plugin version 3.54.10 or earlier is affected. The vulnerability resides in the JSON‑LD REST API component of the plugin, so all sites running WordLift up through and including 3.54.10 are potentially exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk, and the EPSS score of less than 1% suggests that, as of this assessment, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog, which further reduces the urgency relative to actively exploited flaws. Nonetheless, because the attack path requires no authentication and only involves simple HTTP GET requests to predictable endpoints, an attacker can easily gather sensitive post metadata. The vulnerability is best classified under CWE‑200: Information Exposure.

Generated by OpenCVE AI on September 19, 2026 at 23:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WordLift plugin to the latest version (≥3.54.11) where the REST endpoints are secured with proper permission checks.
  • If an immediate upgrade is not feasible, temporarily block or remove the /wordlift/v1/jsonld/ routes by editing the plugin’s code or by adding a security plugin that restricts unauthenticated REST access.
  • As a broader security measure, restrict anonymous REST API access globally by setting the REST API permissions to require authentication, or disable the JSON‑LD feature on the site until the issue is resolved.

Generated by OpenCVE AI on September 19, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordlift
Wordlift wordlift – Ai Powered Seo – Schema
Wordpress
Wordpress wordpress
Vendors & Products Wordlift
Wordlift wordlift – Ai Powered Seo – Schema
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is due to the plugin registering the /wordlift/v1/jsonld/ routes (jsonld/{id}, jsonld/http/{item_id}, jsonld/post-meta/{meta_key}, jsonld/meta/{meta_key}, and jsonld/{post_type}/{post_name}) with a permission_callback of '__return_true' and the downstream converter retrieving the post via get_post() without verifying the post status or the requesting user's capabilities. This makes it possible for unauthenticated attackers to read the title, content/description, author, publication and modification dates, word count, comment count, and other metadata of private, draft, and pending posts by enumerating post IDs, bypassing WordPress core access controls.
Title WordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API Endpoints
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordlift Wordlift – Ai Powered Seo – Schema
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T13:51:19.390Z

Reserved: 2026-05-22T16:49:50.517Z

Link: CVE-2026-9289

cve-icon Vulnrichment

Updated: 2026-09-19T13:49:11.519Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T09:16:34.917

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-9289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor