The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts, which will execute when a user accesses an injected page. The crafted payload uses only WordPress-permitted comment tags and attributes. Defenders should assess exposure and prioritize verificat [truncated]
The CVE-2026-6101 vulnerability is an Arbitrary File Write issue in the AMP for WP – Accelerated Mobile Pages plugin for WordPress. This vulnerability exists due to unsafe ZIP file extraction in the ampforwp_save_local_font() function, combined with inadequate cleanup that fails to remove nested directories and files. Authenticated attackers with Author-level access and above, and permissions granted by a [truncated]