CVE-2021-23150: WordPress AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
Published Mar 18, 2022
·Updated
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.
Affected Software
1 affected component
Ampforwp Accelerated Mobile Pages Wordpress<=1.0.77.31
Remediation
Information
Update to 1.0.77.32 or higher version.
Event History
Mar 18, 2022
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-23150?
The severity of CVE-2021-23150 is medium with a severity value of 4.8.
2
What is the description of CVE-2021-23150?
CVE-2021-23150 is an authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions.
3
What software versions are affected by CVE-2021-23150?
The affected software versions of CVE-2021-23150 are AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-23150?
The Common Weakness Enumeration (CWE) ID for CVE-2021-23150 is CWE-79.
5
How can I fix the CVE-2021-23150 vulnerability?
To fix the CVE-2021-23150 vulnerability, it is recommended to update the AMP for WP – Accelerated Mobile Pages plugin to a version higher than 1.0.77.31.