MEDIUM
wordlift
CVE published 2026-09-19
CVE-2026-9289
The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10. This vulnerability allows unauthenticated attackers to read metadata of private, draft, and pending posts by enumerating post IDs, bypassing WordPress core access controls. The plugin's JSON-LD REST API endpoints are registered with a permission_callbac [truncated]