MEDIUM
CVE-2026-82124
CVSS
5.3
Description
The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more than one public output route.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
0.33%
Probability of exploitation in next 30 days
26.4th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.