CVE · Medium

CVE-2024-6896 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.97

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6896 AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.97 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.0.97 1.0.97 2024-07-23

CVE-2024-6896

The AMP for WP – Accelerated Mobile Pages plugin contains a security flaw allowing malicious SVG uploads to introduce unauthorized JavaScript code into WordPress sites, which can be executed by users who view these files. This vulnerability affects all plugin versions up to and including 1.0.96.1, regardless of the site's configuration or user permissions. Authorized users with at least Author-level access can exploit this weakness to inject arbitrary web scripts that will run when accessed through the uploaded SVG file.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.