CVE-2024-11254: AMP for WP – Accelerated Mobile Pages <= 1.1.1 - Reflected Cross-Site Scripting
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqusname parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11254?
CVE-2024-11254 has a medium severity level due to the potential for reflected Cross-Site Scripting attacks.
How do I fix CVE-2024-11254?
To fix CVE-2024-11254, update the AMP for WP – Accelerated Mobile Pages plugin to version 1.1.2 or later.
What impact does CVE-2024-11254 have on my site?
CVE-2024-11254 allows an unauthenticated attacker to inject malicious scripts into your site through the disqus_name parameter.
Which versions of AMP for WP are affected by CVE-2024-11254?
All versions of the AMP for WP – Accelerated Mobile Pages plugin up to and including 1.1.1 are affected by CVE-2024-11254.
Who can exploit CVE-2024-11254?
CVE-2024-11254 can be exploited by unauthenticated attackers, making it especially dangerous for websites using vulnerable versions.