Thursday, 11 December 2025
26.2 C
Singapore
22.1 C
Thailand
20.7 C
Indonesia
27.1 C
Philippines

WordPress plugin vulnerability impacts over 100,000 sites

A critical update for the WordPress Accelerated Mobile Pages plugin addresses a security flaw impacting over 100,000 sites, underscoring the importance of regular updates.

A popular WordPress plugin, Accelerated Mobile Pages, used by over 100,000 websites, recently addressed a medium-severity security flaw. This vulnerability could have let attackers inject harmful scripts, impacting website visitors.

Understanding the vulnerability

Cross-site scripting (XSS) is a common security issue, particularly in WordPress plugins. It arises when a plugin’s data input isn’t adequately secured, allowing unauthorised data like scripts or zip files to be inserted. In the case of the Accelerated Mobile Pages plugin, this issue stemmed from handling shortcodes.

Shortcodes in WordPress let users easily integrate plugin functionalities within posts and pages. However, if these shortcodes are not properly secured, they can become a gateway for attackers to inject malicious scripts.

The specifics of the flaw

Wordfence, a security firm, detailed the nature of the vulnerability in the Accelerated Mobile Pages plugin. The flaw was present in all versions up to 1.0.88.1 due to inadequate sanitisation of user inputs in the plugin’s shortcodes. This inadequacy allowed attackers with at least contributor-level access to exploit the vulnerability.

Patchstack, another security company, rated this exploit as having medium severity with a 6.5 score out of 10. They recommended users update their plugin to version 1.0.89 or later to mitigate the risk.

Protecting your site

For website administrators using this plugin, ensuring that the latest update is installed is crucial. Regularly updating plugins is critical to maintaining website security and protecting against such vulnerabilities.

Read the full Patchstack report on the vulnerability here:

WordPress Accelerated Mobile Pages Plugin <= 1.0.88.1 is vulnerable to Cross Site Scripting (XSS)

Also, find the detailed announcement by Wordfence here:

Accelerated Mobile Pages <= 1.0.88.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Hot this week

Deepal marks Christmas in Singapore with Pantler Café collaboration and S07 test drive giveaway

Deepal partners with Pantler Café in Singapore for festive treats, an S07 showcase and a 3D2N electric SUV test drive giveaway.

EOY music, comics and arts festival returns with new venue and expanded programme

EOY 2025 returns with a new venue, international guests and expanded activities celebrating Japanese pop culture in Singapore.

Tiger Brokers: Bringing institutional-grade AI intelligence to global retail investors

AI is redefining retail investing as platforms like Tiger Brokers’ TigerAI integrate verified intelligence, personalisation, and long-term wealth management to empower global investors.

Kayou debuts at Singapore Comic Con 2025 with focus on Southeast Asia expansion

Kayou marks its debut at Singapore Comic Con 2025 and outlines plans to expand its retail network and fan community efforts across Southeast Asia.

UnionBank adopts Amazon Quick Suite to accelerate data-driven decision making

UnionBank deploys Amazon Quick Suite to expand access to data analytics and speed up decision making across its organisation.

Affinidi launches pilot to speed up cross-border employment verification

Affinidi launches a pilot to cut cross-border employment verification from weeks to minutes using reusable digital credentials.

Airwallex acquires majority stake in Indonesian payments firm to deepen Asia-Pacific expansion

Airwallex acquires majority ownership of PT Skye Sab Indonesia to expand its financial infrastructure across Asia-Pacific.

Busways launches ultra-fast charging hub in northern Singapore

Busways has opened Singapore’s first ultra-fast charging hub in the north, supporting electric commercial and industrial fleets.

Developers in Australia and India build new network API solutions at Nokia and Telstra hackathon

Developers create new prototypes using network APIs at Nokia and Telstra’s Connected Future Hackathon 2025.

Related Articles

Popular Categories