CVE-2026-9067

CRITICAL

Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-9067. PoCs published by Polosss.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-9067, an unauthenticated arbitrary file upload vulnerability in the Schema & Structured Data for WP & AMP plugin. The exploit includes Python and Bash scripts to extract nonces and upload files via AJAX endpoints.

Description

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos.

Exploits (1)

nomisec WORKING POC
by Polosss · poc
https://github.com/Polosss/By-Poloss..-..CVE-2026-9067

This repository contains a functional exploit for CVE-2026-9067, an unauthenticated arbitrary file upload vulnerability in the Schema & Structured Data for WP & AMP plugin. The exploit includes Python and Bash scripts to extract nonces and upload files via AJAX endpoints.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Schema & Structured Data for WP & AMP < 1.60
No auth needed
Prerequisites: WordPress site with vulnerable plugin installed · Review form rendered on at least one page for nonce extraction
devstral-2 · analyzed Jun 11, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/7fac98eb-f82c-4705-a956-aba650945826/

Scores

CVSS v3 9.1
EPSS 0.0026
EPSS Percentile 16.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
None/Schema & Structured Data for WP & AMP < 1.60
Published Jun 10, 2026
Tracked Since Jun 10, 2026