PT-2026-56191 · WordPress · Amp For Wp

·

CVE-2026-6101

·

Published

2026-07-07

·

Updated

2026-07-08

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AMP for WP versions prior to 1.1.13
Description An Arbitrary File Write issue exists due to unsafe ZIP file extraction within the ampforwp save local font() function, coupled with inadequate cleanup that fails to remove nested directories and files. Authenticated attackers with Author-level access or higher, and permissions granted by an Administrator, can write arbitrary files to a web-accessible location on the server. This may lead to remote code execution on hosts that execute PHP files in the uploads directory.
Recommendations Update the plugin to a version newer than 1.1.12.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6101

Affected Products

Amp For Wp