CVE · High

CVE-2026-6101 — AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6101 AMP for WP – Accelerated Mobile Pages [accelerated-mobile-pages] < 1.1.13 External Control of File Name or Path High 7.5 < 1.1.13 1.1.13 2026-07-06

CVE-2026-6101

The AMP for WP plugin contains a security flaw that allows malicious users with administrator-level privileges or higher to create arbitrary files on the server. This is due to an issue with how the plugin handles ZIP file extraction and subsequent cleanup, resulting in vulnerable directories being left intact. As a consequence, attackers can potentially write executable code to the uploads directory, giving them unauthorized access to the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.