CVE Database /
CVE-2024-9598
CVE · High
CVE-2024-9598 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.99.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-9598
|
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.99.2 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 1.0.99.2
|
1.0.99.2 |
2024-10-24 |
—
|
CVE-2024-9598
The AMP for WP – Accelerated Mobile Pages plugin has a security flaw that affects all versions up to 1.0.99.1, allowing malicious actors to exploit Cross-Site Request Forgery vulnerabilities. This issue arises from inadequate validation of nonces in the 'proxy' function, which can be manipulated by attackers to send legitimate users' cookies to their own server. A site administrator's unwitting action, such as clicking a link, can trigger this vulnerability.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings