Tuesday, 28 October 2025
27.2 C
Singapore
23.9 C
Thailand
20.3 C
Indonesia
27.5 C
Philippines

WordPress plugin vulnerability impacts over 100,000 sites

A critical update for the WordPress Accelerated Mobile Pages plugin addresses a security flaw impacting over 100,000 sites, underscoring the importance of regular updates.

A popular WordPress plugin, Accelerated Mobile Pages, used by over 100,000 websites, recently addressed a medium-severity security flaw. This vulnerability could have let attackers inject harmful scripts, impacting website visitors.

Understanding the vulnerability

Cross-site scripting (XSS) is a common security issue, particularly in WordPress plugins. It arises when a plugin’s data input isn’t adequately secured, allowing unauthorised data like scripts or zip files to be inserted. In the case of the Accelerated Mobile Pages plugin, this issue stemmed from handling shortcodes.

Shortcodes in WordPress let users easily integrate plugin functionalities within posts and pages. However, if these shortcodes are not properly secured, they can become a gateway for attackers to inject malicious scripts.

The specifics of the flaw

Wordfence, a security firm, detailed the nature of the vulnerability in the Accelerated Mobile Pages plugin. The flaw was present in all versions up to 1.0.88.1 due to inadequate sanitisation of user inputs in the plugin’s shortcodes. This inadequacy allowed attackers with at least contributor-level access to exploit the vulnerability.

Patchstack, another security company, rated this exploit as having medium severity with a 6.5 score out of 10. They recommended users update their plugin to version 1.0.89 or later to mitigate the risk.

Protecting your site

For website administrators using this plugin, ensuring that the latest update is installed is crucial. Regularly updating plugins is critical to maintaining website security and protecting against such vulnerabilities.

Read the full Patchstack report on the vulnerability here:

WordPress Accelerated Mobile Pages Plugin <= 1.0.88.1 is vulnerable to Cross Site Scripting (XSS)

Also, find the detailed announcement by Wordfence here:

Accelerated Mobile Pages <= 1.0.88.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Hot this week

Rubrik introduces Agent Cloud to accelerate secure enterprise AI adoption

Rubrik launches Agent Cloud, a new platform enabling enterprises to monitor, govern, and undo AI agent actions across major platforms.

Ledger unveils Nano Gen5, redefining the crypto wallet as a personal digital signer

Ledger launches the Nano Gen5, redefining its crypto wallet as a secure digital identity signer for the modern online world.

Whisker introduces Litter-Robot 5 Pro with AI facial recognition for cats

Whisker introduces the Litter-Robot 5 Pro, featuring AI facial recognition and new smart features for advanced cat care.

Lenovo unveils agentic AI to power the next generation of AI-enabled workforces

Lenovo expands its AI-Enabled Workforce with new agentic AI capabilities to boost productivity, security, and measurable ROI.

Microsoft releases emergency Windows 11 update to fix recovery bug

Microsoft has issued an emergency Windows 11 update to fix a recovery bug that disabled USB mouse and keyboard support in WinRE.

OnePlus 15 launches in China with global release expected soon

OnePlus launches the OnePlus 15 in China with a powerful chipset, a 165Hz display, and a 7,300mAh battery, with a global release expected soon.

Adobe adds iPhone 17 support to Project Indigo, but selfie camera remains disabled

Adobe updates Project Indigo to support iPhone 17, but temporarily disables the selfie camera while full compatibility is being developed.

Samsung One UI 8.5 may introduce a new notification prioritisation tool

Samsung’s upcoming One UI 8.5 update may include a new tool that prioritises important notifications to improve alert management.

Neato cloud shutdown leaves robot vacuums limited to manual operation

Neato’s cloud services are shutting down, leaving its robot vacuums without app control and limited to manual operation.

Related Articles