AMP for WP Released Patch For a Massive Security Flaw
AMP for WP, a popular WordPress plugin with more than 100,000 downloads, has come under the limelight for all the wrong reasons.
The plugin’s vulnerability was highlighted last week in WebARX blog where it published a proof of concept code on how to exploit it. Attackers took no time in responding and started exploiting it after which the plugin was removed from the official WordPress repository.
A similar vulnerability was discovered in WP GDPR compliance plugin. The vulnerability allowed attackers to use the plugin’s code to make changes on the website.
The vulnerability in AMP for WP plugin was originally discovered by Sybre Waaijer, a Dutch security researcher who discovered and reported the vulnerability to the developers back in October of this year.
AMP for WP is now back as the developers worked around a patch that would fix the vulnerability. If you are one of the thousands of users of this plugin, it is highly recommended that you download the patch right away.
Subscribe to Get a FREE WordPress Ebook Right in Your Inbox
WPblog provides the complete guide to launch your WordPress website completely FREE!
Moeez is ‘The’ blogger in charge of WPblog. He loves to interact and learn about WordPress with people in the WordPress community. Outside his work life, Moeez spends time hanging out with his friends, playing Xbox and watching football on the weekends. You can get in touch with him at moeez[at]wpblog.com.