Thursday, 21 November 2024
26.9 C
Singapore

WordPress plugin vulnerability impacts over 100,000 sites

A critical update for the WordPress Accelerated Mobile Pages plugin addresses a security flaw impacting over 100,000 sites, underscoring the importance of regular updates.

A popular WordPress plugin, Accelerated Mobile Pages, used by over 100,000 websites, recently addressed a medium-severity flaw. This vulnerability could have let attackers inject harmful scripts, impacting visitors.

Understanding the vulnerability

Cross-site scripting (XSS) is a common security issue, particularly in WordPress plugins. It arises when a plugin’s data input isn’t adequately secured, allowing unauthorised data like scripts or zip files to be inserted. In the case of the Accelerated Mobile Pages plugin, this issue stemmed from handling shortcodes.

Shortcodes in WordPress let users easily integrate plugin functionalities within posts and pages. However, if these shortcodes are not properly secured, they can become a gateway for attackers to inject malicious scripts.

The specifics of the flaw

Wordfence, a security firm, detailed the nature of the vulnerability in the Accelerated Mobile Pages plugin. The flaw was present in all versions up to 1.0.88.1 due to inadequate sanitisation of user inputs in the plugin’s shortcodes. This inadequacy allowed attackers with at least contributor-level access to exploit the vulnerability.

Patchstack, another security company, rated this exploit as having medium severity with a 6.5 score out of 10. They recommended users update their plugin to version 1.0.89 or later to mitigate the risk.

Protecting your site

For website administrators using this plugin, ensuring that the latest update is installed is crucial. Regularly updating plugins is critical to maintaining website security and protecting against such vulnerabilities.

Read the full Patchstack report on the vulnerability here:

WordPress Accelerated Mobile Pages Plugin <= 1.0.88.1 is vulnerable to Cross Site Scripting (XSS)

Also, find the detailed announcement by Wordfence here:

Accelerated Mobile Pages <= 1.0.88.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Hot this week

Warrix enhances internal communications with Slack to boost collaboration and efficiency

Warrix has transformed its internal communications with Slack, cutting time spent on meetings and improving collaboration by 30%.

LG wins multiple CES 2025 innovation awards

LG wins over 20 CES 2025 awards, including three Best of Innovation Awards, highlighting its smart life solutions, OLED TVs, and gaming monitors.

US confirms US$6.6 billion CHIPS Act funding for TSMC

TSMC secures US$6.6 billion in CHIPS Act grants to expand in Arizona, marking a milestone in US semiconductor development and job creation.

OPPO Singapore launches ‘Find 24-Hour Miracle’ photography contest

OPPO Singapore launches the #Find24HourMiracle photography contest, inviting participants to capture Singapore’s beauty with the new OPPO Find X8 Series.

ASUS unveils next-generation infrastructure solutions at SC24 with NVIDIA and Ubitus collaboration

ASUS unveils next-gen AI infrastructure solutions at SC24, featuring AI servers, advanced cooling, and green-energy data centres.

NVIDIA expands DLSS 3 support to over 600 games, including Stalker 2

NVIDIA expands DLSS 3 support to over 600 games, including Stalker 2 and Flight Simulator 2024, with improved visuals and performance.

ASUS-built supercomputer with NVIDIA HGX H100 ranked among the world’s top supercomputers

ASUS and Ubilink build a supercomputing facility ranked 31st on TOP500 and 44th on Green500, delivering 45.82 PFLOPS and unmatched efficiency.

OPPO unveils Find X8 and Find X8 Pro with Hasselblad cameras, enhanced performance, and ColorOS 15

Discover OPPO’s Find X8 Series with Hasselblad cameras, AI features, and ColorOS 15. Available globally with premium design and cutting-edge tech.

Canon Singapore and Temasek Polytechnic join forces to boost security training

Canon Singapore partners with Temasek Polytechnic to establish a Security Technology Experience Centre, enhancing training for security professionals in Singapore.

Related Articles

Popular Categories