Friday, 29 August 2025
30.3 C
Singapore
36.4 C
Thailand
28.3 C
Indonesia
27.6 C
Philippines

WordPress plugin vulnerability impacts over 100,000 sites

A critical update for the WordPress Accelerated Mobile Pages plugin addresses a security flaw impacting over 100,000 sites, underscoring the importance of regular updates.

A popular WordPress plugin, Accelerated Mobile Pages, used by over 100,000 websites, recently addressed a medium-severity security flaw. This vulnerability could have let attackers inject harmful scripts, impacting website visitors.

Understanding the vulnerability

Cross-site scripting (XSS) is a common security issue, particularly in WordPress plugins. It arises when a plugin’s data input isn’t adequately secured, allowing unauthorised data like scripts or zip files to be inserted. In the case of the Accelerated Mobile Pages plugin, this issue stemmed from handling shortcodes.

Shortcodes in WordPress let users easily integrate plugin functionalities within posts and pages. However, if these shortcodes are not properly secured, they can become a gateway for attackers to inject malicious scripts.

The specifics of the flaw

Wordfence, a security firm, detailed the nature of the vulnerability in the Accelerated Mobile Pages plugin. The flaw was present in all versions up to 1.0.88.1 due to inadequate sanitisation of user inputs in the plugin’s shortcodes. This inadequacy allowed attackers with at least contributor-level access to exploit the vulnerability.

Patchstack, another security company, rated this exploit as having medium severity with a 6.5 score out of 10. They recommended users update their plugin to version 1.0.89 or later to mitigate the risk.

Protecting your site

For website administrators using this plugin, ensuring that the latest update is installed is crucial. Regularly updating plugins is critical to maintaining website security and protecting against such vulnerabilities.

Read the full Patchstack report on the vulnerability here:

WordPress Accelerated Mobile Pages Plugin <= 1.0.88.1 is vulnerable to Cross Site Scripting (XSS)

Also, find the detailed announcement by Wordfence here:

Accelerated Mobile Pages <= 1.0.88.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Hot this week

Chipolo unveils rechargeable Loop and Card Bluetooth trackers

Chipolo launches its first rechargeable Bluetooth trackers, the Loop and Card, offering six-month battery life and IP67 durability.

Malaysia to host road and traffic technology events in November

Malaysia will host My-ARTTE 2025 and MRMC in November, highlighting innovation in road safety, maintenance, and traffic technology.

Pure Storage reports strong second quarter results and raises guidance

Pure Storage posts 13% revenue growth in Q2 FY26, raises full-year outlook, and highlights new products and industry recognition.

Airwallex wins three honours at Asia FinTech Awards 2025

Airwallex wins three awards at the Asia FinTech Awards 2025, including Banking Tech of the Year, Best Employer, and Director of the Year.

Zoho showcases AI-powered business solutions at Zoholics Hong Kong

Zoho unveils AI-powered solutions including Zia LLM, Zia Hubs, and enhanced CRM at Zoholics Hong Kong to support business growth.

Thinking Machines partners with OpenAI to accelerate AI adoption in Asia Pacific

Thinking Machines partners with OpenAI to expand enterprise AI adoption across Asia Pacific with training, app design, and leadership programmes.

100 women in tech power Singapore’s digital future as nation marks 60 years

Singapore honours 100 women leaders and 25 young achievers in the SG100WIT 2025 list, marking growing female impact in tech.

Synology introduces AI-powered Office Suite with new AI Console

Synology updates its Office Suite with AI-powered MailPlus, Office, and a new AI Console to boost productivity while ensuring data privacy.

Nvidia CEO says AI spending boom is only beginning

Nvidia CEO Jensen Huang predicts AI spending could reach US$4 trillion by 2030, rejecting fears of a slowdown in chip demand.

Related Articles

Popular Categories