CyberRota Analysis
AI-GeneratedThe vulnerability affects the Schema & Structured Data for WP & AMP plugin versions 1.66 and earlier, allowing for PHP Object Injection due to improper handling of user input. This could lead to remote code execution, enabling attackers to execute arbitrary PHP code on the affected systems. Website administrators using this plugin should prioritize patching to mitigate the risk of exploitation.
CVE
CVE-2026-97291
Severity
HIGH
CVSS
8.8
EPSS
0.29%
Original NVD Description
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.