Vulnerability Details CVE-2024-6896
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.2%
CVSS Severity
CVSS v3 Score 6.4
Products affected by CVE-2024-6896
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:-
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.64
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.64.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.65
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.65.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.65.2
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.66
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.66.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.66.2
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.66.3
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.67
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.68
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.68.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.69
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.69.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.69.2
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.70
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.71
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.71.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.71.2
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.72
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.73
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.74
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.75
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.10
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.11
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.12
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.13
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.14
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.15
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.16
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.17
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.2
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.3
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.4
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.5
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.6
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.7
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.8
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.76.9
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.10
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.11
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.12
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.13
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.14
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.15
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.16
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.17
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.18
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.19
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.2
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.20
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.21
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.22
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.23
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.24
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.25
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.26
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.27
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.28
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.29
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.3
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.30
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.31
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.32
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.33
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.34
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.35
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.36
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.37
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.37.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.38
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.39
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.4
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.40
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.41
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.42
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.43
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.44
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.45
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.46
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.47
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.48
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.49
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.5
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.50
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.51
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.52
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.53
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.54
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.54.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.55
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.55.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.6
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.7
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.8
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.77.9
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.78
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.79
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.80
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.81
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.82
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.83
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.84
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.85
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.87
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.88
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.88.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.89
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.90
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.91
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.91.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.92
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.92.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.93
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.93.1
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.93.2
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.94
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.95
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.96
-
cpe:2.3:a:ampforwp:accelerated_mobile_pages:1.0.96.1