Tuesday, 15 July 2025
29.9 C
Singapore
35 C
Thailand
25.4 C
Indonesia
29.8 C
Philippines

WordPress plugin vulnerability impacts over 100,000 sites

A critical update for the WordPress Accelerated Mobile Pages plugin addresses a security flaw impacting over 100,000 sites, underscoring the importance of regular updates.

A popular WordPress plugin, Accelerated Mobile Pages, used by over 100,000 websites, recently addressed a medium-severity security flaw. This vulnerability could have let attackers inject harmful scripts, impacting website visitors.

Understanding the vulnerability

Cross-site scripting (XSS) is a common security issue, particularly in WordPress plugins. It arises when a plugin’s data input isn’t adequately secured, allowing unauthorised data like scripts or zip files to be inserted. In the case of the Accelerated Mobile Pages plugin, this issue stemmed from handling shortcodes.

Shortcodes in WordPress let users easily integrate plugin functionalities within posts and pages. However, if these shortcodes are not properly secured, they can become a gateway for attackers to inject malicious scripts.

The specifics of the flaw

Wordfence, a security firm, detailed the nature of the vulnerability in the Accelerated Mobile Pages plugin. The flaw was present in all versions up to 1.0.88.1 due to inadequate sanitisation of user inputs in the plugin’s shortcodes. This inadequacy allowed attackers with at least contributor-level access to exploit the vulnerability.

Patchstack, another security company, rated this exploit as having medium severity with a 6.5 score out of 10. They recommended users update their plugin to version 1.0.89 or later to mitigate the risk.

Protecting your site

For website administrators using this plugin, ensuring that the latest update is installed is crucial. Regularly updating plugins is critical to maintaining website security and protecting against such vulnerabilities.

Read the full Patchstack report on the vulnerability here:

WordPress Accelerated Mobile Pages Plugin <= 1.0.88.1 is vulnerable to Cross Site Scripting (XSS)

Also, find the detailed announcement by Wordfence here:

Accelerated Mobile Pages <= 1.0.88.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Hot this week

Apple products from Southeast Asia to face new import duties

New US tariffs may increase prices for Apple products like Macs and Watches made in Southeast Asia, starting August 1.

Singapore to get Huawei’s 480kW ultra-fast EV charger by the end of 2025

Huawei brings 480kW ultra-fast EV charger to Singapore by late 2025, slashing charge times and boosting support for commercial vehicles.

Rubio meets with China’s Wang Yi amid growing trade and defence tensions

Rubio meets China’s Wang Yi in Malaysia amid trade tensions, with both sides pushing for influence over Southeast Asia’s future.

Samsung unveils slimmer Galaxy Z Fold7 with big camera and AI upgrades

Samsung launches its thinnest foldable yet, the Galaxy Z Fold7, featuring a 200MP camera, enhanced AI capabilities, and a larger display.

Apple accused of stalling browser competition on iOS despite EU ruling

Apple faces backlash over iOS browser rules as developers struggle to launch non-WebKit engines despite the EU’s DMA ruling.

Google plans to merge ChromeOS and Android into one unified platform

Google confirms plans to combine Android and ChromeOS into one platform, bringing big changes to phones, laptops, and tablets.

Apple accused of stalling browser competition on iOS despite EU ruling

Apple faces backlash over iOS browser rules as developers struggle to launch non-WebKit engines despite the EU’s DMA ruling.

Microsoft will stop new Office 365 features on Windows 10 in 2026

Microsoft will stop new Microsoft 365 features for Windows 10 users starting August 2026, with full support ending by early 2027.

imoo Watch Phone X10 review: Possibly the best kids’ smartwatch for families today

The imoo Watch Phone X10 is a smart, durable kids’ smartwatch with 4G, GPS, dual cameras, and safety features for everyday use.

Related Articles

Popular Categories