MEDIUM

CVE-2026-82125

2026-09-16 CVSS v3.1
CVSS
5.3

Description

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comments still awaiting moderation or marked as spam.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)

EPSS Score

0.31%
Probability of exploitation in next 30 days
23.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE