CVE-2024-9598: AMP for WP – Accelerated Mobile Pages <= 1.0.99.1 - Cross-Site Request Forgery to Privilege Escalation
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's cookies to their own server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9598?
The severity of CVE-2024-9598 is considered medium due to its potential for Cross-Site Request Forgery attacks.
How do I fix CVE-2024-9598?
To fix CVE-2024-9598, update the AMP for WP – Accelerated Mobile Pages plugin to version 1.0.99.2 or later.
What versions are affected by CVE-2024-9598?
CVE-2024-9598 affects all versions of the AMP for WP – Accelerated Mobile Pages plugin up to and including version 1.0.99.1.
What type of vulnerability is CVE-2024-9598?
CVE-2024-9598 is a Cross-Site Request Forgery (CSRF) vulnerability.
Can CVE-2024-9598 be exploited without authentication?
Yes, CVE-2024-9598 can be exploited by unauthenticated attackers due to missing nonce validation.