- AMP for WP <= 1.1.10 - authenticated (contributor+) stored cross-site scripting v... CVE-2026-0627

- AMP for WP <= 1.1.10 - authenticated (contributor+) stored cross-site scripting v... CVE-2026-0627

CVE ID : CVE-2026-0627 Published : Jan. 9, 2026, 8:20 a.m. | 48 minutes ago Description : The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file content that only removes `

CVE Details

Published
Jan. 9, 2026
Affected Product: WordPress

Source: Telegram CVE Monitor