{"api_version":"1","generated_at":"2026-09-16T07:44:01+00:00","cve":"CVE-2026-82124","urls":{"html":"https://cve.report/CVE-2026-82124","api":"https://cve.report/api/cve/CVE-2026-82124.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-82124","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-82124"},"summary":{"title":"Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output","description":"The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more than one public output route.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-16 06:16:33","updated_at":"2026-09-16 06:16:33"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/16c65787-c43a-42c6-94b8-5f748a1b0b25/","name":"https://wpscan.com/vulnerability/16c65787-c43a-42c6-94b8-5f748a1b0b25/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-82124","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82124","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Schema & Structured Data for WP & AMP","version":"affected 1.66 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Revanth Hari Narayana Matte","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Schema & Structured Data for WP & AMP","vendor":"Unknown","versions":[{"lessThan":"1.66","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Revanth Hari Narayana Matte"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more than one public output route."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T06:00:12.494Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/16c65787-c43a-42c6-94b8-5f748a1b0b25/"}],"source":{"discovery":"EXTERNAL"},"title":"Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-82124","datePublished":"2026-09-16T06:00:12.494Z","dateReserved":"2026-08-28T07:01:48.230Z","dateUpdated":"2026-09-16T06:00:12.494Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 06:16:33","lastModifiedDate":"2026-09-16 06:16:33","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"82124","Ordinal":"1","Title":"Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated P","CVE":"CVE-2026-82124","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"82124","Ordinal":"1","NoteData":"The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more than one public output route.","Type":"Description","Title":"Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated P"}]}}}