CVE-2026-82124: Unknown Schema & Structured Data For Wp & Amp
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more than one public output route.
Affected products
- Unknown Schema & Structured Data For Wp & Amp: before 1.66 (fixed in 1.66)
Published 2026-09-16. Last modified 2026-09-17.