Executive brief
The Schema & Structured Data for WP & AMP WordPress plugin fails to properly enforce access controls when generating schema content. A contributor-level user can access and view the content of draft, pending, private, and password-protected posts created by other users, exposing sensitive unpublished content that should remain restricted.
Technical details
This is a broken access control vulnerability (CWE-284) in the schema generation feature of the plugin. The vulnerability exists because the plugin does not verify that the user requesting schema generation has permission to edit the specific post being targeted. A contributor or higher-privileged user can exploit this by requesting schema generation for posts authored by others, allowing them to read restricted content including draft, pending, private, and password-protected posts. The issue affects versions 1.63 through 1.65, and has been patched in version 1.66.
Affected products
- Schema & Structured Data for WP & AMP Schema & Structured Data for WP & AMP before 1.66
Timeline
- 2026-09-14: disclosed
- 2026-09-16: patched: Fixed in version 1.66