CVE-2026-9289: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in wordlift WordLift – AI powered SEO – Schema
The WordLift – AI powered SEO – Schema plugin for WordPress up to version 3.54.10 has a vulnerability that allows unauthenticated attackers to access sensitive information from private, draft, and pending posts. This occurs because the plugin's JSON-LD REST API endpoints do not enforce proper permission checks, exposing post metadata and content by enumerating post IDs.
AI Analysis
Technical Summary
CVE-2026-9289 is a sensitive information exposure vulnerability in the WordLift – AI powered SEO – Schema WordPress plugin versions up to 3.54.10. The plugin registers several JSON-LD REST API routes with a permission callback that always returns true, allowing unauthenticated access. The downstream code retrieves posts via get_post() without verifying post status or user capabilities, enabling attackers to read titles, content, authorship, publication and modification dates, word counts, comment counts, and other metadata of non-public posts by enumerating post IDs, thereby bypassing WordPress core access controls.
Potential Impact
An unauthenticated attacker can access sensitive information from private, draft, and pending posts, including content and metadata, which should normally be restricted. This exposure can lead to information disclosure but does not affect integrity or availability.
Mitigation Recommendations
No official patch or fix is currently confirmed. Users should monitor the vendor advisory for updates. Until a fix is available, consider disabling the affected JSON-LD REST API endpoints or restricting access to them via custom access controls or firewall rules to prevent unauthorized information disclosure.
CVE-2026-9289: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in wordlift WordLift – AI powered SEO – Schema
Description
The WordLift – AI powered SEO – Schema plugin for WordPress up to version 3.54.10 has a vulnerability that allows unauthenticated attackers to access sensitive information from private, draft, and pending posts. This occurs because the plugin's JSON-LD REST API endpoints do not enforce proper permission checks, exposing post metadata and content by enumerating post IDs.
CVSS v3.1
Score 5.3medium
Affected software
wordlift
WordLift – AI powered SEO – Schema
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-9289 is a sensitive information exposure vulnerability in the WordLift – AI powered SEO – Schema WordPress plugin versions up to 3.54.10. The plugin registers several JSON-LD REST API routes with a permission callback that always returns true, allowing unauthenticated access. The downstream code retrieves posts via get_post() without verifying post status or user capabilities, enabling attackers to read titles, content, authorship, publication and modification dates, word counts, comment counts, and other metadata of non-public posts by enumerating post IDs, thereby bypassing WordPress core access controls.
Potential Impact
An unauthenticated attacker can access sensitive information from private, draft, and pending posts, including content and metadata, which should normally be restricted. This exposure can lead to information disclosure but does not affect integrity or availability.
Mitigation Recommendations
No official patch or fix is currently confirmed. Users should monitor the vendor advisory for updates. Until a fix is available, consider disabling the affected JSON-LD REST API endpoints or restricting access to them via custom access controls or firewall rules to prevent unauthorized information disclosure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-05-22T16:49:50.517Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aae488655bf5e2cf553a405
Added to database: 09/19/2026, 08:32:06 UTC
Last enriched: 09/19/2026, 08:46:44 UTC
Last updated: 09/19/2026, 08:46:44 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.