CVE-2021-23209: WordPress AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.32 - Multiple Auth. Stored Cross-Site Scripting (XSS) vulnerabilities
Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0.77.32).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-23209?
CVE-2021-23209 is a vulnerability discovered in the AMP for WP - Accelerated Mobile Pages WordPress plugin.
What is the severity of CVE-2021-23209?
The severity of CVE-2021-23209 is medium with a CVSS score of 4.8.
How can an attacker exploit the CVE-2021-23209 vulnerability?
An attacker with admin user role can exploit the CVE-2021-23209 vulnerability by executing persistent Cross-Site Scripting (XSS) attacks.
Which versions of the AMP for WP plugin are affected by CVE-2021-23209?
Versions up to and including 1.0.77.32 of the AMP for WP - Accelerated Mobile Pages plugin are affected by CVE-2021-23209.
Is there a patch available for CVE-2021-23209?
Yes, a patch for CVE-2021-23209 is available. It is recommended to update to the latest version of the AMP for WP - Accelerated Mobile Pages plugin to mitigate the vulnerability.