CVE-2026-82125: Unknown Schema & Structured Data For Wp & Amp
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comments still awaiting moderation or marked as spam.
Affected products
- Unknown Schema & Structured Data For Wp & Amp: from 1.46, before 1.66 (fixed in 1.66)
Published 2026-09-16. Last modified 2026-09-17.