N/A
2026-01-08< 1.1.11
AMP for WP <= 1.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG File Upload
Minimum safe version
1.1.11
Update to 1.1.11 or later to address 16 fixable vulnerabilities
AMP for WP <= 1.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG File Upload
CVE-2025-14468
CVE-2024-11254
CVE-2024-9598
CVE-2024-43146
CVE-2024-6896
CVE-2024-1043
CVE-2024-0587
WordPress AMP for WP Plugin <= 1.0.92 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-48321
AMP for WP <= 0.9.97.19 - Missing Authorization
Accelerated Mobile Pages <= 0.9.97.19 - Multiple Unauthenticated Vulnerabilities
WordPress Accelerated Mobile Pages plugin <= 0.9.97.19 - Multiple Unauthenticated Vulnerabilities
CVE-2021-23209
CVE-2021-23150
CVE-2018-20838