CVE-2026-82124: Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output
The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more than one public output route.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated user who can access a public output route generated by the plugin may be able to retrieve content from password-protected posts. No authentication is required.
Which installations are affected?
Installations using Schema & Structured Data for WP & AMP versions earlier than 1.66 are affected. The issue concerns the plugin's structured-data output for password-protected posts.
What should be done if immediate updating is not possible?
The provided information does not identify a workaround. Restricting public access to affected password-protected content or disabling the plugin's structured-data output may reduce exposure, but these mitigations are not confirmed by the source data.