cleantalk
Vulnerabilities and Security Researches

AMP for WP – Accelerated Mobile Pages, eedf963d25cfe4d2433c77958cf227780fc0b388

Published on
Oct 20, 2018
Research Description
AMP for WP &#8211; Accelerated Mobile Pages [accelerated-mobile-pages] < 0.9.97.20 AMP for WP <= 0.9.97.19 - Missing Authorization TheAMP for WP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ampforwp_save_steps_data AJAX hook in versions up to, and including, 0.9.97.19. This makes it possible for authenticated attackers to make otherwise privilege locked administrative changes to the vulnerable website and create admin accounts.
Affected versions
max 0.9.97.20.
Status
vulnerable