plugin

Accelerated Mobile Pages Vulnerabilities

30 known security issues reported for the Accelerated Mobile Pages WordPress plugin. Most recent disclosed Jul 6, 2026.

2 high 13 medium

Running Accelerated Mobile Pages on your site? Check whether your installed version is affected.

Scan your site free

AMP for WP <= 1.1.12 - Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload

high

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to remove nested directories and files. This makes...

CVSS:
7.5
Affected:
up to 1.1.12
Fixed in:
1.1.13
Disclosed:
Jul 6, 2026

CVE-2026-6101 on NVD →

AMP for WP <= 1.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG File Upload

medium

The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file content that only removes `<script>` tags while allowing other XSS vectors such as event handlers (onload, onerror, onm...

CVSS:
6.4
Affected:
up to 1.1.10
Fixed in:
1.1.11
Disclosed:
Jan 8, 2026

CVE-2026-0627 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.10

unknown

[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to inverted nonce verification logic in the amp_theme_ajaxcomments AJAX handler, which rejects requests with VALID nonces and accepts requests with MISSING...

Affected:
up to 1.1.10
Fixed in:
1.1.10
Disclosed:
Jan 7, 2026

CVE-2025-14468 on NVD →

AMP for WP – Accelerated Mobile Pages <= 1.1.9 - Cross-Site Request Forgery to Comment Submission

medium

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to inverted nonce verification logic in the amp_theme_ajaxcomments AJAX handler, which rejects requests with VALID nonces and accepts requests with MISSING or I...

CVSS:
4.3
Affected:
up to 1.1.9
Fixed in:
1.1.10
Disclosed:
Jan 6, 2026

CVE-2025-14468 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.2

unknown

[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Dec 18, 2024

CVE-2024-11254 on NVD →

AMP for WP – Accelerated Mobile Pages <= 1.1.1 - Reflected Cross-Site Scripting

medium

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
6.1
Affected:
up to 1.1.1
Fixed in:
1.1.2
Disclosed:
Dec 17, 2024

CVE-2024-11254 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.97

unknown

[en] Missing Authorization vulnerability in Ahmed Kaludi, Mohammed Kaludi AMP for WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AMP for WP: from n/a through 1.0.96.1.

Affected:
up to 1.0.97
Fixed in:
1.0.97
Disclosed:
Nov 1, 2024

CVE-2024-43146 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.99.2

unknown

[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's...

Affected:
up to 1.0.99.2
Fixed in:
1.0.99.2
Disclosed:
Oct 25, 2024

CVE-2024-9598 on NVD →

AMP for WP – Accelerated Mobile Pages <= 1.0.99.1 - Cross-Site Request Forgery to Privilege Escalation

high

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's cooki...

CVSS:
8.8
Affected:
up to 1.0.99.1
Fixed in:
1.0.99.2
Disclosed:
Oct 24, 2024

CVE-2024-9598 on NVD →

AMP for WP <= 1.0.96.1 - Missing Authorization

medium

The AMP for WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions like 'enable_amp_pagebuilder' and 'amppb_save_layout_data' in versions up to, and including, 1.0.96.1. This makes it possible for authenticated attackers, with contributor-level...

CVSS:
4.3
Affected:
up to 1.0.96.1
Fixed in:
1.0.97
Disclosed:
Aug 7, 2024

CVE-2024-43146 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.97

unknown

[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access an...

Affected:
up to 1.0.97
Fixed in:
1.0.97
Disclosed:
Jul 24, 2024

CVE-2024-6896 on NVD →

AMP for WP – Accelerated Mobile Pages <= 1.0.96.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abo...

CVSS:
6.4
Affected:
up to 1.0.96.1
Fixed in:
1.0.97
Disclosed:
Jul 23, 2024

CVE-2024-6896 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.93.2

unknown

[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access an...

Affected:
up to 1.0.93.2
Fixed in:
1.0.93.2
Disclosed:
Feb 20, 2024

CVE-2024-1043 on NVD →

AMP for WP <= 1.0.93.1 - Authenticated(Contributor+) Arbitrary Post Deletion via amppb_remove_saved_layout_data

medium

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access and abo...

CVSS:
6.5
Affected:
up to 1.0.93.1
Fixed in:
1.0.93.2
Disclosed:
Feb 6, 2024

CVE-2024-1043 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.93

unknown

[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticate...

Affected:
up to 1.0.93
Fixed in:
1.0.93
Disclosed:
Jan 23, 2024

CVE-2024-0587 on NVD →

Accelerated Mobile Pages <= 1.0.92.1 - Reflected Cross-Site Scripting

medium

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticated att...

CVSS:
6.1
Affected:
up to 1.0.92.1
Fixed in:
1.0.93
Disclosed:
Jan 22, 2024

CVE-2024-0587 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.92.1

unknown

[en] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...

Affected:
up to 1.0.92.1
Fixed in:
1.0.92.1
Disclosed:
Jan 11, 2024

CVE-2023-6782 on NVD →

AMP for WP – Accelerated Mobile Pages <= 1.0.92 - Authenticated (Contributor+) Cross-Site Scripting via Shortcode

medium

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker...

CVSS:
6.4
Affected:
up to 1.0.92
Fixed in:
1.0.92.1
Disclosed:
Dec 18, 2023

CVE-2023-6782 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.89

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmed Kaludi, Mohammed Kaludi AMP for WP – Accelerated Mobile Pages allows Stored XSS.This issue affects AMP for WP – Accelerated Mobile Pages: from n/a through 1.0.88.1.

Affected:
up to 1.0.89
Fixed in:
1.0.89
Disclosed:
Nov 30, 2023

CVE-2023-48321 on NVD →

Accelerated Mobile Pages <= 1.0.88.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.88.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 1.0.88.1
Fixed in:
1.0.89
Disclosed:
Nov 28, 2023

CVE-2023-48321 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.77.33

unknown

[en] Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.

Affected:
up to 1.0.77.33
Fixed in:
1.0.77.33
Disclosed:
Mar 18, 2022

CVE-2021-23150 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.77.33

unknown

[en] Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).

Affected:
up to 1.0.77.33
Fixed in:
1.0.77.33
Disclosed:
Mar 18, 2022

CVE-2021-23209 on NVD →

AMP for WP <= 1.0.77.32 - Authenticated Stored Cross-Site Scripting

medium

Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).

CVSS:
5.5
Affected:
up to 1.0.77.32
Fixed in:
1.0.77.33
Disclosed:
Dec 15, 2021

CVE-2021-23209 on NVD →

AMP for WP – Accelerated Mobile Pages <= 1.0.77.31 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.31).

CVSS:
5.5
Affected:
up to 1.0.77.31
Fixed in:
1.0.77.32
Disclosed:
Dec 11, 2021

CVE-2021-23150 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 0.9.97.21

unknown

[en] ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.

Affected:
up to 0.9.97.21
Fixed in:
0.9.97.21
Disclosed:
May 13, 2019

CVE-2018-20838 on NVD →

AMP for WP <= 0.9.97.20 - Stored Cross-Site Scripting

medium

ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.

CVSS:
5.4
Affected:
up to 0.9.97.20
Fixed in:
0.9.97.21
Disclosed:
Nov 20, 2018

CVE-2018-20838 on NVD →

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 0.9.97.20

unknown

Multiple Unauthenticated Vulnerabilities found in WordPress Accelerated Mobile Pages plugin (versions <= 0.9.97.19).

Affected:
up to 0.9.97.20
Fixed in:
0.9.97.20
Disclosed:
Nov 13, 2018

AMP for WP <= 0.9.97.19 - Missing Authorization

medium

TheAMP for WP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ampforwp_save_steps_data AJAX hook in versions up to, and including, 0.9.97.19. This makes it possible for authenticated attackers to make otherwise privilege locked administrative changes to the vulnerable...

CVSS:
6.3
Affected:
up to 0.9.97.19
Fixed in:
0.9.97.20
Disclosed:
Oct 20, 2018

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 0.9.97.20

unknown

TheAMP for WP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ampforwp_save_steps_data AJAX hook in versions up to, and including, 0.9.97.19. This makes it possible for authenticated attackers to make otherwise privilege locked administrative changes to the vulnerable...

Affected:
up to 0.9.97.20
Fixed in:
0.9.97.20
Disclosed:
Oct 20, 2018

AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 0.9.97.20

unknown

The AMP for WP &ndash; Accelerated Mobile Pages WordPress plugin was affected by a Multiple Unauthenticated Vulnerabilities security vulnerability.

Affected:
up to 0.9.97.20
Fixed in:
0.9.97.20

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database