AMP for WP <= 1.1.12 - Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload
high
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to remove nested directories and files. This makes...
- CVSS:
- 7.5
- Affected:
- up to 1.1.12
- Fixed in:
- 1.1.13
- Disclosed:
- Jul 6, 2026
CVE-2026-6101 on NVD →
AMP for WP <= 1.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG File Upload
medium
The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file content that only removes `<script>` tags while allowing other XSS vectors such as event handlers (onload, onerror, onm...
- CVSS:
- 6.4
- Affected:
- up to 1.1.10
- Fixed in:
- 1.1.11
- Disclosed:
- Jan 8, 2026
CVE-2026-0627 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.10
unknown
[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to inverted nonce verification logic in the amp_theme_ajaxcomments AJAX handler, which rejects requests with VALID nonces and accepts requests with MISSING...
- Affected:
- up to 1.1.10
- Fixed in:
- 1.1.10
- Disclosed:
- Jan 7, 2026
CVE-2025-14468 on NVD →
AMP for WP – Accelerated Mobile Pages <= 1.1.9 - Cross-Site Request Forgery to Comment Submission
medium
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to inverted nonce verification logic in the amp_theme_ajaxcomments AJAX handler, which rejects requests with VALID nonces and accepts requests with MISSING or I...
- CVSS:
- 4.3
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.10
- Disclosed:
- Jan 6, 2026
CVE-2025-14468 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.2
unknown
[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Dec 18, 2024
CVE-2024-11254 on NVD →
AMP for WP – Accelerated Mobile Pages <= 1.1.1 - Reflected Cross-Site Scripting
medium
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.1
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.2
- Disclosed:
- Dec 17, 2024
CVE-2024-11254 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.97
unknown
[en] Missing Authorization vulnerability in Ahmed Kaludi, Mohammed Kaludi AMP for WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AMP for WP: from n/a through 1.0.96.1.
- Affected:
- up to 1.0.97
- Fixed in:
- 1.0.97
- Disclosed:
- Nov 1, 2024
CVE-2024-43146 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.99.2
unknown
[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's...
- Affected:
- up to 1.0.99.2
- Fixed in:
- 1.0.99.2
- Disclosed:
- Oct 25, 2024
CVE-2024-9598 on NVD →
AMP for WP – Accelerated Mobile Pages <= 1.0.99.1 - Cross-Site Request Forgery to Privilege Escalation
high
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's cooki...
- CVSS:
- 8.8
- Affected:
- up to 1.0.99.1
- Fixed in:
- 1.0.99.2
- Disclosed:
- Oct 24, 2024
CVE-2024-9598 on NVD →
AMP for WP <= 1.0.96.1 - Missing Authorization
medium
The AMP for WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions like 'enable_amp_pagebuilder' and 'amppb_save_layout_data' in versions up to, and including, 1.0.96.1. This makes it possible for authenticated attackers, with contributor-level...
- CVSS:
- 4.3
- Affected:
- up to 1.0.96.1
- Fixed in:
- 1.0.97
- Disclosed:
- Aug 7, 2024
CVE-2024-43146 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.97
unknown
[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access an...
- Affected:
- up to 1.0.97
- Fixed in:
- 1.0.97
- Disclosed:
- Jul 24, 2024
CVE-2024-6896 on NVD →
AMP for WP – Accelerated Mobile Pages <= 1.0.96.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
medium
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abo...
- CVSS:
- 6.4
- Affected:
- up to 1.0.96.1
- Fixed in:
- 1.0.97
- Disclosed:
- Jul 23, 2024
CVE-2024-6896 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.93.2
unknown
[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access an...
- Affected:
- up to 1.0.93.2
- Fixed in:
- 1.0.93.2
- Disclosed:
- Feb 20, 2024
CVE-2024-1043 on NVD →
AMP for WP <= 1.0.93.1 - Authenticated(Contributor+) Arbitrary Post Deletion via amppb_remove_saved_layout_data
medium
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access and abo...
- CVSS:
- 6.5
- Affected:
- up to 1.0.93.1
- Fixed in:
- 1.0.93.2
- Disclosed:
- Feb 6, 2024
CVE-2024-1043 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.93
unknown
[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticate...
- Affected:
- up to 1.0.93
- Fixed in:
- 1.0.93
- Disclosed:
- Jan 23, 2024
CVE-2024-0587 on NVD →
Accelerated Mobile Pages <= 1.0.92.1 - Reflected Cross-Site Scripting
medium
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticated att...
- CVSS:
- 6.1
- Affected:
- up to 1.0.92.1
- Fixed in:
- 1.0.93
- Disclosed:
- Jan 22, 2024
CVE-2024-0587 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.92.1
unknown
[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- Affected:
- up to 1.0.92.1
- Fixed in:
- 1.0.92.1
- Disclosed:
- Jan 11, 2024
CVE-2023-6782 on NVD →
AMP for WP – Accelerated Mobile Pages <= 1.0.92 - Authenticated (Contributor+) Cross-Site Scripting via Shortcode
medium
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...
- CVSS:
- 6.4
- Affected:
- up to 1.0.92
- Fixed in:
- 1.0.92.1
- Disclosed:
- Dec 18, 2023
CVE-2023-6782 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.89
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmed Kaludi, Mohammed Kaludi AMP for WP – Accelerated Mobile Pages allows Stored XSS.This issue affects AMP for WP – Accelerated Mobile Pages: from n/a through 1.0.88.1.
- Affected:
- up to 1.0.89
- Fixed in:
- 1.0.89
- Disclosed:
- Nov 30, 2023
CVE-2023-48321 on NVD →
Accelerated Mobile Pages <= 1.0.88.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
medium
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.88.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 1.0.88.1
- Fixed in:
- 1.0.89
- Disclosed:
- Nov 28, 2023
CVE-2023-48321 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.77.33
unknown
[en] Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.
- Affected:
- up to 1.0.77.33
- Fixed in:
- 1.0.77.33
- Disclosed:
- Mar 18, 2022
CVE-2021-23150 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.77.33
unknown
[en] Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).
- Affected:
- up to 1.0.77.33
- Fixed in:
- 1.0.77.33
- Disclosed:
- Mar 18, 2022
CVE-2021-23209 on NVD →
AMP for WP <= 1.0.77.32 - Authenticated Stored Cross-Site Scripting
medium
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).
- CVSS:
- 5.5
- Affected:
- up to 1.0.77.32
- Fixed in:
- 1.0.77.33
- Disclosed:
- Dec 15, 2021
CVE-2021-23209 on NVD →
AMP for WP – Accelerated Mobile Pages <= 1.0.77.31 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.31).
- CVSS:
- 5.5
- Affected:
- up to 1.0.77.31
- Fixed in:
- 1.0.77.32
- Disclosed:
- Dec 11, 2021
CVE-2021-23150 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 0.9.97.21
unknown
[en] ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.
- Affected:
- up to 0.9.97.21
- Fixed in:
- 0.9.97.21
- Disclosed:
- May 13, 2019
CVE-2018-20838 on NVD →
AMP for WP <= 0.9.97.20 - Stored Cross-Site Scripting
medium
ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.
- CVSS:
- 5.4
- Affected:
- up to 0.9.97.20
- Fixed in:
- 0.9.97.21
- Disclosed:
- Nov 20, 2018
CVE-2018-20838 on NVD →
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 0.9.97.20
unknown
Multiple Unauthenticated Vulnerabilities found in WordPress Accelerated Mobile Pages plugin (versions <= 0.9.97.19).
- Affected:
- up to 0.9.97.20
- Fixed in:
- 0.9.97.20
- Disclosed:
- Nov 13, 2018
AMP for WP <= 0.9.97.19 - Missing Authorization
medium
TheAMP for WP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ampforwp_save_steps_data AJAX hook in versions up to, and including, 0.9.97.19. This makes it possible for authenticated attackers to make otherwise privilege locked administrative changes to the vulnerable...
- CVSS:
- 6.3
- Affected:
- up to 0.9.97.19
- Fixed in:
- 0.9.97.20
- Disclosed:
- Oct 20, 2018
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 0.9.97.20
unknown
TheAMP for WP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ampforwp_save_steps_data AJAX hook in versions up to, and including, 0.9.97.19. This makes it possible for authenticated attackers to make otherwise privilege locked administrative changes to the vulnerable...
- Affected:
- up to 0.9.97.20
- Fixed in:
- 0.9.97.20
- Disclosed:
- Oct 20, 2018
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 0.9.97.20
unknown
The AMP for WP – Accelerated Mobile Pages WordPress plugin was affected by a Multiple Unauthenticated Vulnerabilities security vulnerability.
- Affected:
- up to 0.9.97.20
- Fixed in:
- 0.9.97.20
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database