---
id: CVE-2026-82126
title: >-
  The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does
  not check that a user is allowed to edit the specific post they request schema
  generation for, allowing users with the contributor role and above to obtain
  the c…
summary: >-
  The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does
  not check that a user is allowed to edit the specific post they request schema
  generation for, allowing users with the contributor role and above to obtain
  the c…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-284
product: Schema & Structured Data for WP & AMP
affected:
  - schema_structured_data_for_wp_amp >= 1.63 < 1.66
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:49.000'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82126'
references:
  - url: 'https://wpscan.com/vulnerability/c6476bdd-1360-449f-b7be-6c532efe9de9/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:20:12.315557Z'
epss: 0.00299
epssPercentile: 0.20071
ingestedAt: '2026-09-16T06:51:06.248Z'
---

## Overview

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the content of other users' draft, pending, private and password protected posts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
