CVE-2026-82125
Received
Received - Intake
Unauthenticated Comment Content Exposure in Schema & Structured Data for WP & AMP
Vulnerability report for CVE-2026-82125, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-16
Last updated on: 2026-09-16
Assigner: WPScan
Description
Description
The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comments still awaiting moderation or marked as spam.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wp_schema_and_structured_data | plugin | 1.46 |
| wp_schema_and_structured_data | plugin | 1.47 |
| wp_schema_and_structured_data | plugin | 1.48 |
| wp_schema_and_structured_data | plugin | 1.49 |
| wp_schema_and_structured_data | plugin | 1.50 |
| wp_schema_and_structured_data | plugin | 1.51 |
| wp_schema_and_structured_data | plugin | 1.52 |
| wp_schema_and_structured_data | plugin | 1.53 |
| wp_schema_and_structured_data | plugin | 1.54 |
| wp_schema_and_structured_data | plugin | 1.55 |
| wp_schema_and_structured_data | plugin | 1.56 |
| wp_schema_and_structured_data | plugin | 1.57 |
| wp_schema_and_structured_data | plugin | 1.58 |
| wp_schema_and_structured_data | plugin | 1.59 |
| wp_schema_and_structured_data | plugin | 1.60 |
| wp_schema_and_structured_data | plugin | 1.61 |
| wp_schema_and_structured_data | plugin | 1.62 |
| wp_schema_and_structured_data | plugin | 1.63 |
| wp_schema_and_structured_data | plugin | 1.64 |
| wp_schema_and_structured_data | plugin | 1.65 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |