PT-2024-16275 · WordPress · Amp For Wp – Accelerated Mobile Pages

Sean Murphy

·

Published

2024-02-20

·

Updated

2024-02-29

·

CVE-2024-1043

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AMP for WP – Accelerated Mobile Pages plugin for WordPress versions up to, and including, 1.0.93.1
Description The issue is related to unauthorized loss of data due to a missing capability check on the amppb remove saved layout data function. This allows authenticated attackers with contributor access and above to delete arbitrary posts on the site.
Recommendations For versions up to, and including, 1.0.93.1, consider disabling the amppb remove saved layout data function until a patch is available to prevent unauthorized data loss. Restrict access to the function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1043

Affected Products

Amp For Wp – Accelerated Mobile Pages