CVE · Medium

CVE-2024-43146 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.97

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-43146 AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.0.97 Missing Authorization Medium 6.3 < 1.0.97 1.0.97 2024-08-07

CVE-2024-43146

The AMP for WP plugin for WordPress contains a capability check deficiency that permits authenticated users with contributor permissions or higher to alter plugin settings and page layouts through functions such as 'enable_amp_pagebuilder' and 'amppb_save_layout_data'. This vulnerability affects versions 1.0.96.1 and earlier, allowing attackers to make unauthorized modifications to data that should be restricted to administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.