Executive brief
The Schema & Structured Data for WP & AMP WordPress plugin returns the content of moderation-pending and spam-flagged comments without properly validating user permissions. This allows anyone—even unauthenticated visitors—to read comments that site administrators have hidden from public view, potentially exposing sensitive information or work-in-progress discussions.
Technical details
This is an indirect object reference (IDOR) vulnerability in the comment handling logic. The plugin fails to verify comment ownership or moderation status before exposing comment content to unauthenticated users. An attacker can access non-public comment data by requesting comments through the plugin's API or interface without authentication. The vulnerability affects versions 1.46 through 1.65; version 1.66 and later include the fix. No active wild exploitation has been reported at publication time.
Affected products
- Automattic Schema & Structured Data for WP & AMP 1.46-1.65
Timeline
- 2026-09-14: disclosed
- 2026-09-16: patched: Version 1.66 released with fix
- 2026-09-16: advisory