8.8
CVE-2024-9598
- EPSS 0.41%
- Veröffentlicht 25.10.2024 08:15:03
- Zuletzt bearbeitet 21.02.2025 20:47:35
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
AMP for WP – Accelerated Mobile Pages <= 1.0.99.1 - Cross-Site Request Forgery to Privilege Escalation
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's cookies to their own server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Mögliche Gegenmaßnahme
AMP for WP – Accelerated Mobile Pages: Update to version 1.0.99.2, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
AMP for WP – Accelerated Mobile Pages
Version
* - 1.0.99.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ampforwp ≫ Accelerated Mobile Pages SwPlatformwordpress Version < 1.0.99.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.603 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.