Overview
- Description
- The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the logged in user's cookies to their own server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Source
- security@wordfence.com
- NVD status
- Awaiting Analysis
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Weaknesses
- security@wordfence.com
- CWE-352
Social media
- Hype score
- Not currently trending
[CVE-2024-9598: HIGH] Warning: Vulnerability found in AMP for WP plugin for WordPress. Missing nonce validation could allow unauthenticated attackers to steal user cookies. Update to version 1.0.99.2 to stay secure.#cybersecurity,#vulnerability https://t.co/AcyPHxI73o https://t.c
@CveFindCom
25 Oct 2024
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-9598 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due t… https://t.co/667YY702zz
@CVEnew
25 Oct 2024
373 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes