Ampforwp develops a plugin for WordPress that implements the Accelerated Mobile Pages framework, extending WordPress's mobile optimization capabilities. The vendor's vulnerability profile centers on application-layer weaknesses endemic to web plugins: cross-site scripting, cross-site request forgery, and authorization flaws that recur across the Ampforwp ecosystem. Defenders should treat this vendor's plugin advisories as part of broader WordPress supply-chain risk management, where patch velocity and deployment breadth across WordPress instances matter more than individual CVE volume; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ampforwp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9598HIGH The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or | Oct 25, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-1043MEDIUM The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' | Feb 29, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-11254MEDIUM The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1 | Dec 18, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-0587MEDIUM The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up to, and including, | Jan 23, 2024 | 6.1 | 19 | NO | NO |
CVE-2021-23209MEDIUM Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP – Accelerated Mobile Pages WordPress plugin (versions <= 1.0 | Mar 18, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-23150MEDIUM Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pages plugin <= 1.0.77.31 versions. | Mar 18, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-6896MEDIUM The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due | Jul 24, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ampforwp.
Media articles that mention a CVE ID that affects a product developed by Ampforwp — matched by CVE ID, not by vendor name.