PT-2026-93290 · WordPress · Schema & Structured Data For Wp & Amp
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Schema & Structured Data for WP & AMP versions prior to 1.66
Description
Insufficient authorization checks during schema generation allow users with the contributor role or higher to access the content of posts they are not permitted to edit. This includes draft, pending, private, and password-protected posts created by other users.
Recommendations
Update to version 1.66 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Schema & Structured Data For Wp & Amp