PT-2026-48389 · WordPress · Schema & Structured Data For Wp & Amp

·

CVE-2026-9067

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Schema & Structured Data for WP & AMP versions prior to 1.60
Description The plugin fails to verify user capabilities within its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the intended media type of the endpoint. This allows unauthenticated users to upload any file type supported by the WordPress media library through endpoints that are specifically intended to accept only images or videos.
Recommendations Update to version 1.60 or later.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9067

Affected Products

Schema & Structured Data For Wp & Amp