CVE · Medium

CVE-2025-14468 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14468 AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.10 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.1.10 1.1.10 2026-01-06

CVE-2025-14468

The AMP for WP – Accelerated Mobile Pages WordPress plugin contains a security flaw in versions prior to 1.2 that allows malicious actors to manipulate comments by exploiting a weakness in nonce verification within the amp_theme_ajaxcomments AJAX handler. Specifically, this vulnerability enables an attacker to bypass authentication checks and submit comments on behalf of legitimate users if they can deceive someone into performing a certain action while the plugin's template mode is active.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.