5.4

CVE-2018-20838

Exploit

AMP for WP <= 0.9.97.20 - Stored Cross-Site Scripting

ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.
Mögliche Gegenmaßnahme
AMP for WP – Accelerated Mobile Pages: Update to version 0.9.97.21, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Magazine3Amp For Wp SwPlatformwordpress Version < 0.9.97.21
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt AMP for WP – Accelerated Mobile Pages
Version *-0.9.97.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.08% 0.607
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://ampforwp.com/critical-security-issues-has-been-fixed-in-0-9-97-20-version/
https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/changelog.txt
Third Party Advisory
Release Notes
https://wordpress.org/plugins/accelerated-mobile-pages/#developers
Third Party Advisory
Release Notes
https://www.wordfence.com/blog/2018/11/xss-injection-campaign-exploits-wordpress-amp-plugin/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/64a833df-1cb8-40a1-9a8f-c53dcf50c877
Third Party Advisory