OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-97291

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects the Schema & Structured Data for WP & AMP plugin versions 1.66 and earlier, allowing for PHP Object Injection due to improper handling of user input. This could lead to remote code execution, enabling attackers to execute arbitrary PHP code on the affected systems. Website administrators using this plugin should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-97291
Severity
HIGH
CVSS
8.8
EPSS
0.29%

Original NVD Description

Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.