---
id: CVE-2026-82124
title: >-
  The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does
  not check whether a post is password protected before including its content in
  the structured data it generates, allowing unauthenticated users to obtain the
  con…
summary: >-
  The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does
  not check whether a post is password protected before including its content in
  the structured data it generates, allowing unauthenticated users to obtain the
  con…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: Schema & Structured Data for WP & AMP
affected:
  - schema_structured_data_for_wp_amp < 1.66
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:48.653'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82124'
references:
  - url: 'https://wpscan.com/vulnerability/16c65787-c43a-42c6-94b8-5f748a1b0b25/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T12:20:46.422977Z'
epss: 0.0033
epssPercentile: 0.26377
ingestedAt: '2026-09-16T06:51:06.247Z'
---

## Overview

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the content of password protected posts via more than one public output route.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
