Stored Cross-Site Scripting Vulnerability in AMP for WP Plugin by WordPress
CVE-2026-83591

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 September 2026

What is CVE-2026-83591?

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is susceptible to a Stored Cross-Site Scripting attack through comment content due to inadequate input sanitization and output escaping. Unauthenticated attackers can exploit this vulnerability, allowing them to inject harmful web scripts into pages. These scripts execute whenever a user accesses the compromised page. The crafted payload can leverage only the comment tags and attributes permitted by WordPress, while the AMP sanitizer fails to adequately block javascript: protocol, leaving the malicious URI introduced by the transformation unfiltered.

Affected Version(s)

AMP for WP – Accelerated Mobile Pages 0 <= 1.1.16

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pham Duc Anh
.