The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's cookies to their own server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Magazine3
Magazine3 amp For Wp |
|
CPEs | cpe:2.3:a:magazine3:amp_for_wp:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Magazine3
Magazine3 amp For Wp |
|
Metrics |
ssvc
|
Fri, 25 Oct 2024 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's cookies to their own server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
Title | AMP for WP – Accelerated Mobile Pages <= 1.0.99.1 - Cross-Site Request Forgery to Privilege Escalation | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-25T07:37:59.702Z
Updated: 2024-10-25T18:54:09.874Z
Reserved: 2024-10-07T17:41:25.727Z
Link: CVE-2024-9598
Vulnrichment
Updated: 2024-10-25T18:54:02.496Z
NVD
Status : Awaiting Analysis
Published: 2024-10-25T08:15:03.250
Modified: 2024-10-25T12:56:07.750
Link: CVE-2024-9598
Redhat
No data.