CVE-2026-97291: WordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
Affected Software
1 affected component
Magazine3 Schema & Structured Data for WP & AMP<=1.66
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Schema & Structured Data for WP & AMP pluginto a version that resolves this vulnerability.Fixed in 1.67
Event History
Sep 30, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Contributor-level access to the affected WordPress site. No user interaction is required.
2
What is the potential impact if the vulnerability is exploited?
The vulnerability is rated high severity with a CVSS score of 8.8. It can affect confidentiality, integrity, and availability, with all three impacts rated high.
3
Which plugin versions are affected?
Schema & Structured Data for WP & AMP versions 1.66 and earlier are affected.