Back to Database
Status published
Medium
CVE-2018-20838
ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for...
Vulnerability Description
ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-20838
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.wordfence.com/blog/2018/11/xss-injection-campaign-exploits-wordpress-amp-plugin/
- https://plugins.trac.wordpress.org/browser/accelerated-mobile-pages/trunk/changelog.txt
- https://wordpress.org/plugins/accelerated-mobile-pages/#developers
- https://ampforwp.com/critical-security-issues-has-been-fixed-in-0-9-97-20-version/
More from magazine3
View All →CVE-2025-14069
Schema & Structured Data for WP & AMP <= 1.54 - Authenticated (Contributor+) Stored Cross-Site Scripting via User Custom Schema
Medium
6.4
CVE-2025-13738
Easy Table of Contents <= 2.0.78 - Authenticated (Contributor+) Stored Cross-Site Scripting
Medium
6.4
CVE-2025-11502
Schema & Structured Data for WP & AMP <= 1.51 - Authenticated (Contributor+) Stored Cross-Site Scripting
Medium
6.4
CVE-2024-5582
Schema & Structured Data for WP & AMP <= 1.33 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Attribute
Medium
6.4
CVE-2024-3491
Schema & Structured Data for WP & AMP <= 1.29 - Authenticated (Contributor+) Stored Cross-Site Scripting via How To and FAQ Blocks
Medium
6.4
Affected Vendor
magazine3
View all reports →Affected Software
amp for wp
Vulnerable Versions:
0
Timeline
Official Publish:
May 13th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.