PT-2026-95805 · WordPress · Wordlift
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WordLift – AI powered SEO – Schema plugin for WordPress versions prior to 3.54.11
Description
Sensitive information exposure occurs via the JSON-LD REST API endpoints. The plugin registers the '/wordlift/v1/jsonld/' routes, specifically 'jsonld/{id}', 'jsonld/http/{item id}', 'jsonld/post-meta/{meta key}', 'jsonld/meta/{meta key}', and 'jsonld/{post type}/{post name}', using a
permission callback of return true. Because the downstream converter uses the get post() function without verifying the post status or the capabilities of the requesting user, unauthenticated attackers can bypass WordPress core access controls. By enumerating post IDs, attackers can access the title, content, author, publication and modification dates, word count, comment count, and other metadata of private, draft, and pending posts.Recommendations
Update WordLift – AI powered SEO – Schema plugin for WordPress to version 3.54.11 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordlift