Tuesday, 11 November 2025
28 C
Singapore
24.7 C
Thailand
20.6 C
Indonesia
28.2 C
Philippines

WordPress plugin vulnerability impacts over 100,000 sites

A critical update for the WordPress Accelerated Mobile Pages plugin addresses a security flaw impacting over 100,000 sites, underscoring the importance of regular updates.

A popular WordPress plugin, Accelerated Mobile Pages, used by over 100,000 websites, recently addressed a medium-severity security flaw. This vulnerability could have let attackers inject harmful scripts, impacting website visitors.

Understanding the vulnerability

Cross-site scripting (XSS) is a common security issue, particularly in WordPress plugins. It arises when a plugin’s data input isn’t adequately secured, allowing unauthorised data like scripts or zip files to be inserted. In the case of the Accelerated Mobile Pages plugin, this issue stemmed from handling shortcodes.

Shortcodes in WordPress let users easily integrate plugin functionalities within posts and pages. However, if these shortcodes are not properly secured, they can become a gateway for attackers to inject malicious scripts.

The specifics of the flaw

Wordfence, a security firm, detailed the nature of the vulnerability in the Accelerated Mobile Pages plugin. The flaw was present in all versions up to 1.0.88.1 due to inadequate sanitisation of user inputs in the plugin’s shortcodes. This inadequacy allowed attackers with at least contributor-level access to exploit the vulnerability.

Patchstack, another security company, rated this exploit as having medium severity with a 6.5 score out of 10. They recommended users update their plugin to version 1.0.89 or later to mitigate the risk.

Protecting your site

For website administrators using this plugin, ensuring that the latest update is installed is crucial. Regularly updating plugins is critical to maintaining website security and protecting against such vulnerabilities.

Read the full Patchstack report on the vulnerability here:

WordPress Accelerated Mobile Pages Plugin <= 1.0.88.1 is vulnerable to Cross Site Scripting (XSS)

Also, find the detailed announcement by Wordfence here:

Accelerated Mobile Pages <= 1.0.88.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Hot this week

Armis secures US$435 million in pre-IPO funding at US$6.1 billion valuation

Armis raises US$435 million in a pre-IPO round led by Goldman Sachs, valuing the cybersecurity firm at US$6.1 billion.

Porsche brings Formula E innovation to the new Cayenne Electric

Porsche brings Formula E racing technology to the new Cayenne Electric, combining high efficiency, fast charging, and advanced cooling.

AI adoption grows 20% in Singapore as 170,000 businesses embrace the technology

AI adoption in Singapore rises 20% in 2025, with 170,000 businesses now using AI across finance, tech, and healthcare sectors.

Tenity concludes SingHacks 2025, Asia’s first fintech-focused agentic AI hackathon

Tenity concludes SingHacks 2025, Asia’s first fintech-focused agentic AI hackathon, ahead of its grand finals at Singapore FinTech Festival.

Motorola launches ultra-thin Edge 70 smartphone in the UK

Motorola launches the ultra-thin Edge 70 smartphone in the UK, featuring triple 50MP cameras, AI tools, and up to 50 hours of battery life.

Singapore FinTech Festival 2025 marks 10 years with focus on the next decade of finance

Singapore FinTech Festival 2025 celebrates its 10th year, spotlighting AI, tokenisation, and quantum technologies shaping global finance.

Adyen launches new payment terminals for retail and F&B sectors

Adyen launches the S1E4 Pro and S1F4 Pro terminals, enhancing in-person payment solutions for retail and F&B businesses.

Startups from Australia, India and UAE named winners in L’Oréal’s 2025 Beauty Tech competition

L’Oréal crowns startups from Australia, India and UAE as winners of its 2025 Beauty Tech Innovation Program in Singapore.

Workato launches AI Lab in Singapore to drive applied AI innovation and workforce development

Workato opens its AI Lab in Singapore to accelerate applied AI innovation, create skilled jobs, and strengthen industry-academia collaboration.

Related Articles

Popular Categories