CVE Database /
CVE-2026-6101
CVE · High
CVE-2026-6101 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-6101
|
AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.13 |
External Control of File Name or Path |
High
7.5
|
< 1.1.13
|
1.1.13 |
2026-07-06 |
—
|
CVE-2026-6101
The AMP for WP plugin contains a security flaw that allows malicious users with administrator-level privileges or higher to create arbitrary files on the server. This is due to an issue with how the plugin handles ZIP file extraction and subsequent cleanup, resulting in vulnerable directories being left intact. As a consequence, attackers can potentially write executable code to the uploads directory, giving them unauthorized access to the server.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings