PatchSiren

wordlift CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wordlift CVE published 2026-09-19

CVE-2026-9289

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10. This vulnerability allows unauthenticated attackers to read metadata of private, draft, and pending posts by enumerating post IDs, bypassing WordPress core access controls. The plugin's JSON-LD REST API endpoints are registered with a permission_callbac [truncated]