Impact
The WordLift – AI powered SEO – Schema plugin for WordPress contains a flaw in its JSON‑LD REST API endpoints. The plugin registers routes such as /wordlift/v1/jsonld/... with a permission callback that always returns true, and the downstream code retrieves posts via get_post() without checking the post status or the requesting user’s capabilities. As a result, unauthenticated users can enumerate post IDs and read the title, content, author, publication and modification dates, word count, comment count, and other metadata for private, draft, and pending posts, bypassing WordPress core access controls. This represents a clear confidentiality breach consistent with CWE‑200.
Affected Systems
Any WordPress installation using WordLift plugin version 3.54.10 or earlier is affected. The vulnerability resides in the JSON‑LD REST API component of the plugin, so all sites running WordLift up through and including 3.54.10 are potentially exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the EPSS score of less than 1% suggests that, as of this assessment, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog, which further reduces the urgency relative to actively exploited flaws. Nonetheless, because the attack path requires no authentication and only involves simple HTTP GET requests to predictable endpoints, an attacker can easily gather sensitive post metadata. The vulnerability is best classified under CWE‑200: Information Exposure.
OpenCVE Enrichment