Sensitive Information Exposure in WordLift – AI Powered SEO Plugin for WordPress
CVE-2026-9289
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-9289?
The WordLift – AI powered SEO – Schema plugin for WordPress has a vulnerability that allows unauthenticated attackers to access sensitive metadata from private, draft, and pending posts through the JSON-LD REST API endpoints. This is due to inadequate permission checks, which enable attackers to bypass access controls, potentially exposing critical information such as post titles, content, authorship details, and other metadata.
Affected Version(s)
WordLift – AI powered SEO – Schema 0 <= 3.54.10