Monday, 22 December 2025
26.9 C
Singapore
21.1 C
Thailand
20.8 C
Indonesia
26.4 C
Philippines

WordPress plugin vulnerability impacts over 100,000 sites

A critical update for the WordPress Accelerated Mobile Pages plugin addresses a security flaw impacting over 100,000 sites, underscoring the importance of regular updates.

A popular WordPress plugin, Accelerated Mobile Pages, used by over 100,000 websites, recently addressed a medium-severity security flaw. This vulnerability could have let attackers inject harmful scripts, impacting website visitors.

Understanding the vulnerability

Cross-site scripting (XSS) is a common security issue, particularly in WordPress plugins. It arises when a plugin’s data input isn’t adequately secured, allowing unauthorised data like scripts or zip files to be inserted. In the case of the Accelerated Mobile Pages plugin, this issue stemmed from handling shortcodes.

Shortcodes in WordPress let users easily integrate plugin functionalities within posts and pages. However, if these shortcodes are not properly secured, they can become a gateway for attackers to inject malicious scripts.

The specifics of the flaw

Wordfence, a security firm, detailed the nature of the vulnerability in the Accelerated Mobile Pages plugin. The flaw was present in all versions up to 1.0.88.1 due to inadequate sanitisation of user inputs in the plugin’s shortcodes. This inadequacy allowed attackers with at least contributor-level access to exploit the vulnerability.

Patchstack, another security company, rated this exploit as having medium severity with a 6.5 score out of 10. They recommended users update their plugin to version 1.0.89 or later to mitigate the risk.

Protecting your site

For website administrators using this plugin, ensuring that the latest update is installed is crucial. Regularly updating plugins is critical to maintaining website security and protecting against such vulnerabilities.

Read the full Patchstack report on the vulnerability here:

WordPress Accelerated Mobile Pages Plugin <= 1.0.88.1 is vulnerable to Cross Site Scripting (XSS)

Also, find the detailed announcement by Wordfence here:

Accelerated Mobile Pages <= 1.0.88.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Hot this week

Huawei unveils Mate X7 foldable phone for global markets

Huawei unveils the global Mate X7 foldable phone in Dubai, detailing design updates, camera improvements, software limits and premium pricing.

Crunchyroll Arc returns to celebrate fandom, connection, and anime’s global rise

Crunchyroll brings back its Arc year-in-review experience, highlighting anime fandom, personalised personas, and the medium’s growing global impact.

Sony brings affordable full-body motion capture to aspiring VTubers in Singapore

Sony launches its Mocopi motion capture system in Singapore, offering VTubers an affordable, smartphone-based way to capture full-body movement.

Antler invests US$5.6 million across 14 AI startups with early commercial traction

Antler invests US$5.6 million in 14 AI startups with early traction, focusing on applied AI and real-world enterprise adoption.

Sony and Honda’s first electric car brings PlayStation Remote Play on the road

Sony and Honda’s Afeela EV will support PlayStation Remote Play, letting passengers stream PS5 and PS4 games to the car’s display.

Google delays Gemini takeover from Assistant on Android until 2026

Google has delayed replacing Google Assistant with Gemini on Android, extending the transition into 2026 as technical challenges persist.

Valve ends production of its last Steam Deck LCD model

Valve ends production of its last Steam Deck LCD model, leaving OLED versions as the only option and raising the entry price for new buyers.

Sony and Honda’s first electric car brings PlayStation Remote Play on the road

Sony and Honda’s Afeela EV will support PlayStation Remote Play, letting passengers stream PS5 and PS4 games to the car’s display.

Samsung unveils Exynos 2600 as first 2nm mobile processor

Samsung unveils the Exynos 2600, the world’s first 2nm mobile chip, expected to debut in the Galaxy S26 in early 2026.

Related Articles

Popular Categories