CVE-2024-1043

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access and above, to delete arbitrary posts on the site.


We have discovered 12,808 live websites that are affected by CVE-2024-1043.

Test my site




Affected Software

Product  AMP for WP
Category Wordpress Plugins
Vulnerable Domains12,808 live websites (28.23% of AMP for WP install base)
Vulnerable Versions
  • from 0 through 1.0.93.1
Vulnerable Versions Count233 versions ( 94.72% of all versions)



Details

  • Published - Feb 20, 2024
  • Updated - Aug 1, 2024

Credits

  • Sean Murphy (finder)

CVE-2024-1043 usage by Country

United States6,266 websites



Germany1,732 websites
Russia808 websites
France722 websites
Japan416 websites
Spain217 websites
GB196 websites
Vietnam192 websites
Italy164 websites
Brazil163 websites

CVE-2024-1043 usage by TLD

.com6,379 websites
.ru994 websites
.net615 websites
.org528 websites
.com.br253 websites
.info223 websites
.fr201 websites
.it194 websites
.de159 websites
.es117 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1043

Top websites that are affected by CVE-2024-1043. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.de Germany**,***
**********.ir Iran**,***
***.********.com United States**,***
*******.de France**,***
******.***.br United States**,***
**********.***.pk Pakistan**,***
*****************.com United States**,***
**********.com United States**,***
**********.fr France**,***
********.com United States**,***
See full domain list

FAQ

A total of 12,808 websites have been identified as vulnerable to CVE-2024-1043, discovered through global website indexing conducted by WebTechSurvey.
AMP for WP is susceptible to CVE-2024-1043 vulnerability.
AMP for WP versions before, and including, 1.0.93.1 are vulnerable to CVE-2024-1043.