CVE Database /
CVE-2025-14468
CVE · Medium
CVE-2025-14468 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.10
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-14468
|
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.10 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 1.1.10
|
1.1.10 |
2026-01-06 |
—
|
CVE-2025-14468
The AMP for WP – Accelerated Mobile Pages WordPress plugin contains a security flaw in versions prior to 1.2 that allows malicious actors to manipulate comments by exploiting a weakness in nonce verification within the amp_theme_ajaxcomments AJAX handler. Specifically, this vulnerability enables an attacker to bypass authentication checks and submit comments on behalf of legitimate users if they can deceive someone into performing a certain action while the plugin's template mode is active.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings