Stored Cross-Site Scripting Vulnerability in AMP for WP Plugin by WordPress
CVE-2026-83591
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-83591?
The AMP for WP β Accelerated Mobile Pages plugin for WordPress is susceptible to a Stored Cross-Site Scripting attack through comment content due to inadequate input sanitization and output escaping. Unauthenticated attackers can exploit this vulnerability, allowing them to inject harmful web scripts into pages. These scripts execute whenever a user accesses the compromised page. The crafted payload can leverage only the comment tags and attributes permitted by WordPress, while the AMP sanitizer fails to adequately block javascript: protocol, leaving the malicious URI introduced by the transformation unfiltered.
Affected Version(s)
AMP for WP β Accelerated Mobile Pages 0 <= 1.1.16