CVE-2024-1043: AMP for WP <= 1.0.93.1 - Authenticated(Contributor+) Arbitrary Post Deletion via amppb_remove_saved_layout_data
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppbremovesavedlayoutdata' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access and above, to delete arbitrary posts on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1043?
CVE-2024-1043 has a medium severity rating due to unauthorized data loss risks.
How do I fix CVE-2024-1043?
To fix CVE-2024-1043, update the AMP for WP – Accelerated Mobile Pages plugin to a version later than 1.0.93.1.
Who is affected by CVE-2024-1043?
All users of the AMP for WP – Accelerated Mobile Pages plugin versions up to and including 1.0.93.1 are affected by CVE-2024-1043.
What kind of attacks can exploit CVE-2024-1043?
CVE-2024-1043 can be exploited by authenticated attackers to perform unauthorized loss of layout data.
Is CVE-2024-1043 specific to certain WordPress versions?
CVE-2024-1043 is not specific to certain WordPress versions, but rather to the AMP for WP plugin versions up to 1.0.93.1.