CVE · Medium

CVE-2024-1043 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.93.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1043 AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.93.2 Improper Authorization Medium 6.5 < 1.0.93.2 1.0.93.2 2024-02-06

CVE-2024-1043

The AMP for WP plugin for WordPress contained a broken access control vulnerability affecting versions before 1.0.93.2, which was discovered by Sean Murphy. The flaw allowed unauthorized users to perform actions reserved for higher-privileged accounts due to missing authorization, authentication, or nonce verification in a specific function. The vulnerability has been resolved in version 1.0.93.2 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.