CVE · High

CVE-2024-9598 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.99.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-9598 AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.99.2 Cross-Site Request Forgery (CSRF) High 8.8 < 1.0.99.2 1.0.99.2 2024-10-24

CVE-2024-9598

The AMP for WP – Accelerated Mobile Pages plugin has a security flaw that affects all versions up to 1.0.99.1, allowing malicious actors to exploit Cross-Site Request Forgery vulnerabilities. This issue arises from inadequate validation of nonces in the 'proxy' function, which can be manipulated by attackers to send legitimate users' cookies to their own server. A site administrator's unwitting action, such as clicking a link, can trigger this vulnerability.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.