CVE-2024-11254
- EPSS 0.23%
- Veröffentlicht 18.12.2024 04:15:07
- Zuletzt bearbeitet 21.02.2025 20:44:25
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for ...
CVE-2024-9598
- EPSS 0.41%
- Veröffentlicht 25.10.2024 08:15:03
- Zuletzt bearbeitet 21.02.2025 20:47:35
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it pos...
CVE-2024-6896
- EPSS 0.18%
- Veröffentlicht 24.07.2024 11:15:11
- Zuletzt bearbeitet 21.11.2024 09:50:29
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. This makes it ...
CVE-2024-1043
- EPSS 0.19%
- Veröffentlicht 29.02.2024 01:43:38
- Zuletzt bearbeitet 26.02.2025 15:14:42
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it...
CVE-2024-0587
- EPSS 2.76%
- Veröffentlicht 23.01.2024 07:15:52
- Zuletzt bearbeitet 21.11.2024 08:46:57
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping o...
CVE-2021-23150
- EPSS 0.3%
- Veröffentlicht 18.03.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:51:17
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.
CVE-2021-23209
- EPSS 0.3%
- Veröffentlicht 18.03.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:51:22
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).