CVE · Medium

CVE-2021-23150 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.77.33

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-23150 AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.77.33 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.0.77.33 1.0.77.33 2021-12-11

CVE-2021-23150

The AMP for WP – Accelerated Mobile Pages plugin through version 1.0.77.31 contains an authenticated stored cross-site scripting vulnerability that allows logged-in users to inject malicious scripts into the website. An attacker with user account access can craft a request that stores JavaScript code, which then executes when other users visit the affected pages. This flaw impacts all installations running version 1.0.77.31 or earlier, and users should upgrade to version 1.0.77.33 or later to remediate the issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.