Saturday, 24 May 2025
27.8 C
Singapore
27.4 C
Thailand
20.1 C
Indonesia
29.4 C
Philippines

WordPress plugin vulnerability impacts over 100,000 sites

A critical update for the WordPress Accelerated Mobile Pages plugin addresses a security flaw impacting over 100,000 sites, underscoring the importance of regular updates.

A popular WordPress plugin, Accelerated Mobile Pages, used by over 100,000 websites, recently addressed a medium-severity security flaw. This vulnerability could have let attackers inject harmful scripts, impacting website visitors.

Understanding the vulnerability

Cross-site scripting (XSS) is a common security issue, particularly in WordPress plugins. It arises when a plugin’s data input isn’t adequately secured, allowing unauthorised data like scripts or zip files to be inserted. In the case of the Accelerated Mobile Pages plugin, this issue stemmed from handling shortcodes.

Shortcodes in WordPress let users easily integrate plugin functionalities within posts and pages. However, if these shortcodes are not properly secured, they can become a gateway for attackers to inject malicious scripts.

The specifics of the flaw

Wordfence, a security firm, detailed the nature of the vulnerability in the Accelerated Mobile Pages plugin. The flaw was present in all versions up to 1.0.88.1 due to inadequate sanitisation of user inputs in the plugin’s shortcodes. This inadequacy allowed attackers with at least contributor-level access to exploit the vulnerability.

Patchstack, another security company, rated this exploit as having medium severity with a 6.5 score out of 10. They recommended users update their plugin to version 1.0.89 or later to mitigate the risk.

Protecting your site

For website administrators using this plugin, ensuring that the latest update is installed is crucial. Regularly updating plugins is critical to maintaining website security and protecting against such vulnerabilities.

Read the full Patchstack report on the vulnerability here:

WordPress Accelerated Mobile Pages Plugin <= 1.0.88.1 is vulnerable to Cross Site Scripting (XSS)

Also, find the detailed announcement by Wordfence here:

Accelerated Mobile Pages <= 1.0.88.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Hot this week

Why is wireless everything finally becoming reality, and what does it mean for you?

Explore how wireless technology is replacing cables across charging, audio, networks, homes, and cars, transforming how we live and work.

SAP unveils new Business AI tools to improve productivity and accelerate cloud adoption

SAP introduces new Business AI tools, partnerships, and solutions to boost productivity and accelerate cloud adoption across enterprises.

NVIDIA supports launch of world’s largest quantum research supercomputer

NVIDIA powers ABCI-Q, the world’s largest quantum research supercomputer, to advance hybrid quantum-AI computing in Japan.

Microsoft brings powerful new Command Palette to Windows users

Microsoft’s new Command Palette makes accessing apps, commands, and files on Windows easier with just a few keystrokes.

Microsoft brings on-device AI to web apps in the Edge browser

Microsoft adds on-device AI to Edge, giving web apps access to Phi-4-mini for smart features like text editing and translation.

Apple could release its first smart glasses in 2026

Apple may launch smart glasses in 2026 with Siri, music, calls, and translation—plus cameras, but not AR just yet.

Xiaomi’s YU7 electric SUV challenges Tesla in China’s booming EV market

Xiaomi’s YU7 electric SUV targets Tesla with 518 miles of range, 3.23s acceleration, and ultra-fast charging in the Chinese EV market.

CapCut updates pricing plans and removes free cloud storage

CapCut updates pricing, removing free cloud storage and raising plan rates, prompting users to reassess their editing and storage needs.

Ricoh to release the much-anticipated GR IV camera this autumn

Ricoh's GR IV camera launches this autumn with new features, improved performance, and a design street photographers will recognise.

Related Articles

Popular Categories