GHSA-44gp-9hmx-cr3cMediumCVSS 5.3

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify...

Published
September 16, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comments still awaiting moderation or marked as spam.

🔗 References (3)