Access violation vulnerability in AMP for WP – Accelerated Mobile Pages 1.0.96.1

The AMP for WP plugin used in WordPress can be changed without permission because it doesn’t check if the user has the right abilities. This issue affects versions 1.0.96.1 and below. This means that attackers who are logged in with contributor-level access or higher can change the plugin’s settings and layouts without authorization.

Detected in:

AMP for WP – Accelerated Mobile Pages fixed vulnerable versions: >= * <= 1.0.96.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.