AMP Vulnerability Provides WP Admin Access

Опубликовано: 30 Июль 2026
на канале: QuickSilk
40
0

If you (or anyone you know) are one of the people that uses AMP for WP — the extremely popular Google Accelerated Mobile Pages (AMP) plugin — you NEED to update your plugin as soon as possible! Recently, AMP for WP was subjected to a massive security vulnerability that put all +100,000 of its users at risk. You can view the full blog post at: https://bit.ly/2DS1CXT

This situation started on October 21st, 2018, when AMP for WP was unexpectedly pulled from the WordPress plugins page. Instead, users were greeted with the text "This plugin was closed on October 21, 2018, and is no longer available for download," which is uniquely strange for anyone that's familiar with WordPress's platform, as a major portion of WordPress's mobile functionality (in relation to speed) is hinged on this popular plugin.

According to the developer, there was "a security Vulnerability in our plugin which could be exploited by non-admins of the site." The ominous message was followed by an unusual pitch: AMP for WP developers were giving users download links for the plugin outside of the WordPress platform. In the same statement, they insisted that: "will submit the new code which will be reviewed and released within a couple of days" followed by the ever reassuring "there's no need to worry."

A couple of days turned into a couple of weeks. In fact, the updated version of AMP for WP wasn't available until November 14th, 2018, which means that it took the developer a full month to patch the flaw. During this month, the publisher was still pushing users to download the plugin, and all those users that already had the plugin were hyper-vulnerable.

So, what was the vulnerability?

AMP for WP allowed any registered user to call an ajax hook that let them change critical plugin functions without checking for their user role. So, whether you're a guest that simply registered to make a comment or you're a writer-privileged account, you could abuse the weak code in the plugin to make significant changes to the WordPress website or blog.

All credit to WebARX and Luka Šikić for finding this vulnerability. You can view the full blog post at: https://bit.ly/2DS1CXT