HomeSecurityUpdate released that fixes vulnerability in popular WordPress plugin

Update released that fixes vulnerability in popular WordPress plugin

vulnerabilityA security researcher has revealed details of a critical vulnerability in one of the popular and widely active plugins for WordPress that could allow a low-privileged attacker to inject malicious code into the AMP pages of the targeted website.

The WordPress vulnerability in question is “AMP for WP – Accelerated Mobile Pages” which allows websites to automatically generate valid mobile pages for their blog posts and other web pages.

AMP ,which stands for Accelerated Mobile Pages, is an open-source technology designed by Google to allow websites to create and deliver faster web pages to mobile users.

Of the hundreds of plugins that allow WordPress sites to create AMP pages, “AMP for WP” is the most popular among the others, with more than 100,000 installations.

The affected plugin was temporarily removed from the WordPress plugins library due to the vulnerable code, but neither the developer nor the WordPress team revealed the exact problem in the plugin.

Cybersecurity researcher Luka Sikic from WebArche analyzed the vulnerable version of the plugin and found a vulnerability in the “AMP for WP” code, which was subsequently patched in its updated version.

The vulnerability worked in such a way that the “AMP for WP – Accelerated Mobile Pages” plugin handled permissions on user accounts and WordPress AJAX.

According to its settings, the plugin offers site administrators options to add ads and custom HTML/JavaScript code to the header or footer of an AMP page. To do this, the plugin uses WordPress built-in /AJAX hooks in the backend.

Since every registered user on a WordPress site is authorized to use AJAX hooks, and since the vulnerable plugin does not check whether the account belongs to the administrator or not, any user of the site can use this feature to insert custom code.

As the researcher has demonstrated in a video, a low-privileged user can simply insert malicious JavaScript into the website.

This vulnerability has been addressed in the latest version 0.9.97.20 of A AMP for WP – Accelerated Mobile Pages.

If your WordPress site uses the affected plugin, we recommend installing the latest available security updates as soon as possible.

Just last week, another arbitrary file deletion vulnerability was revealed in the popular WooCommerce plugin, which could allow a malicious user to gain complete control of WordPress websites.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS