WPIntell

Source evidence

Another Security Vulnerability

Swift SMTP (formerly Welcome Email Editor) 路 support 路 2023-12-05T01:59:00+00:00

mixedsentiment
highseverity
0.88relevance
5replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 32 rows with source links

15.6% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

27 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
dougie24 resolved
Solid Security Pro is flagging this vulnerability in both old and new version 5.0.6: Broken Access Control Vulnerability. Can anything be done to fix this? Thanks D what鈥檚 the flag about? Can you share details please? Thank you! 馃檪 Here鈥檚 what SolidWP is reporting even after upgrade to v5.0.6: DetailsBroken Access Control vulnerability discovered by Abdi Pranata (Patchstack Alliance) in WordPress Plugin Welcome Email Editor (versions <= 5.0.5) Vulnerable versions<= 5.0.5 CVE: CVE-2023-47756 Classification: Broken Access Control Publicly disclosed: November 13, 2023 https://patchstack.com/database/vulnerability/welcome-email-editor/wordpress-welcome-email-editor-plugin-5-0-5-broken-access-control-vulnerability?_a_id=431 Hi David Any update on this issue or should I delete the plugin, because I鈥檓 still receiving vulnerability warnings from Solid Security Pro? Thanks. Guess it鈥檚 time to delete this plugin as no action appears to have been taken. We鈥檝e fixed the vulnerability yesterday and are going to push the update later today 馃檪

Comments

5 shown
David Vongries 2023-12-05T07:02:00+00:00

what鈥檚 the flag about? Can you share details please? Thank you! 馃檪

dougie24 2023-12-05T12:06:00+00:00

Here鈥檚 what SolidWP is reporting even after upgrade to v5.0.6: DetailsBroken Access Control vulnerability discovered by Abdi Pranata (Patchstack Alliance) in WordPress Plugin Welcome Email Editor (versions <= 5.0.5) Vulnerable versions<= 5.0.5 CVE: CVE-2023-47756 Classification: Broken Access Control Publicly disclosed: November 13, 2023 https://patchstack.com/database/vulnerability/welcome-email-editor/wordpress-welcome-email-editor-plugin-5-0-5-broken-access-control-vulnerability?_a_id=431

dougie24 2023-12-07T04:28:00+00:00

Hi David Any update on this issue or should I delete the plugin, because I鈥檓 still receiving vulnerability warnings from Solid Security Pro? Thanks.

dougie24 2023-12-12T02:56:00+00:00

Guess it鈥檚 time to delete this plugin as no action appears to have been taken.

David Vongries 2023-12-12T09:13:00+00:00

We鈥檝e fixed the vulnerability yesterday and are going to push the update later today 馃檪