{"api_version":"1","generated_at":"2026-09-16T07:44:41+00:00","cve":"CVE-2026-82126","urls":{"html":"https://cve.report/CVE-2026-82126","api":"https://cve.report/api/cve/CVE-2026-82126.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-82126","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-82126"},"summary":{"title":"Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public Post Content Disclosure via AI Schema Generation","description":"The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the content of other users' draft, pending, private and password protected posts.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-16 06:16:33","updated_at":"2026-09-16 06:16:33"},"problem_types":["CWE-284 Improper Access Control"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/c6476bdd-1360-449f-b7be-6c532efe9de9/","name":"https://wpscan.com/vulnerability/c6476bdd-1360-449f-b7be-6c532efe9de9/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-82126","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82126","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Schema & Structured Data for WP & AMP","version":"affected 1.63 1.66 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Shirshak","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Schema & Structured Data for WP & AMP","vendor":"Unknown","versions":[{"lessThan":"1.66","status":"affected","version":"1.63","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Shirshak"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the content of other users' draft, pending, private and password protected posts."}],"problemTypes":[{"descriptions":[{"description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T06:00:12.841Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/c6476bdd-1360-449f-b7be-6c532efe9de9/"}],"source":{"discovery":"EXTERNAL"},"title":"Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public Post Content Disclosure via AI Schema Generation","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-82126","datePublished":"2026-09-16T06:00:12.841Z","dateReserved":"2026-08-28T07:01:55.400Z","dateUpdated":"2026-09-16T06:00:12.841Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 06:16:33","lastModifiedDate":"2026-09-16 06:16:33","problem_types":["CWE-284 Improper Access Control"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"82126","Ordinal":"1","Title":"Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+","CVE":"CVE-2026-82126","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"82126","Ordinal":"1","NoteData":"The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the content of other users' draft, pending, private and password protected posts.","Type":"Description","Title":"Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+"}]}}}