CVE-2024-0587: Accelerated Mobile Pages <= 1.0.92.1 - Reflected Cross-Site Scripting
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqusname' parameter in all versions up to, and including, 1.0.92.1 due to insufficient input sanitization and output escaping on the executed JS file. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0587?
CVE-2024-0587 has been rated as a high severity vulnerability due to its potential for enabling reflected cross-site scripting attacks.
How do I fix CVE-2024-0587?
To fix CVE-2024-0587, update the AMP for WP – Accelerated Mobile Pages plugin to version 1.0.92.2 or later.
What type of vulnerability is CVE-2024-0587?
CVE-2024-0587 is a reflected cross-site scripting (XSS) vulnerability.
Which versions of the AMP for WP plugin are affected by CVE-2024-0587?
CVE-2024-0587 affects all versions of the AMP for WP – Accelerated Mobile Pages plugin up to and including 1.0.92.1.
What attack vector is associated with CVE-2024-0587?
CVE-2024-0587 allows attackers to execute malicious scripts through the 'disqus_name' parameter.