The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to inverted nonce verification logic in the amp_theme_ajaxcomments AJAX handler, which rejects requests with VALID nonces and accepts requests with MISSING or INVALID nonces. This makes it possible for unauthenticated attackers to submit comments on behalf of logged-in users via a forged request granted they can trick a user into performing an action such as clicking on a link, and the plugin's template mode is enabled.
We have discovered 31,565 live websites that are affected by CVE-2025-14468.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 31,565 live websites (93% of AMP for WP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 153 versions ( 99% of all versions) |
| 14,785 websites | |
| 2,984 websites | |
| 2,024 websites | |
| 1,756 websites | |
| 788 websites | |
| 761 websites | |
| 709 websites | |
| 675 websites | |
| 664 websites | |
| 615 websites |
| .com | 16,082 websites |
| .ru | 2,959 websites |
| .net | 1,581 websites |
| .org | 1,360 websites |
| .it | 843 websites |
| .com.br | 693 websites |
| .fr | 574 websites |
| .de | 488 websites |
| .info | 404 websites |
| .co.uk | 361 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | *** | ||
| ************.com | **,*** | ||
| **********.ru | **,*** | ||
| *******.fr | **,*** | ||
| ***********.com | **,*** | ||
| ***************.com | **,*** | ||
| *******.de | **,*** | ||
| ***********.com | **,*** | ||
| **********.com | **,*** | ||
| ******.com | **,*** |
FAQ