Skip to main content
Mallory
CriticalPublic exploit

Unauthenticated Arbitrary File Upload in Schema & Structured Data for WP & AMP WordPress Plugin

IdentifiersCVE-2026-9067CWE-434· Unrestricted Upload of File with…

CVE-2026-9067 affects the Schema & Structured Data for WP & AMP WordPress plugin before version 1.60. The plugin's frontend AJAX file-upload handlers do not enforce user capability checks and do not validate the actual uploaded file content against the endpoint's intended media type. As a result, endpoints that are intended to accept only images or videos can be abused by unauthenticated remote attackers to upload any file type that is otherwise accepted by the WordPress media library.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated attacker to place unintended files on the target WordPress site via the vulnerable frontend AJAX upload handlers. This can expose sensitive data and compromise content integrity, consistent with the reported CVSS impacts of high confidentiality and high integrity. The available information does not specifically confirm direct remote code execution, so that outcome cannot be stated with certainty from the provided content alone.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, disable or restrict access to the plugin's frontend AJAX file-upload functionality, especially any unauthenticated upload endpoints. Monitor the WordPress media library and uploads directories for unexpected files, and review site logs for suspicious requests to frontend AJAX upload handlers. Additional hardening should ensure upload endpoints enforce capability checks and strict server-side validation of allowed media types.

Remediation

Patch, then assume compromise.

Update the Schema & Structured Data for WP & AMP plugin to version 1.60 or later, which is the first version not described as affected by this issue.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.