WPIntell

Source evidence

Cross Site Scripting problem

Library Bookshelves · support · 2024-11-19T21:00:00+00:00

mixedsentiment
highseverity
0.82relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

3 / 26 rows with source links

11.5% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

23 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
paulnorko resolved
Hello, I’ve been using the Library Bookshelves on my library’s website (and several other library’s sites in West Virginia, and we love it. However, within the past few days, apparently a Cross Site Scripting Error was discovered and this plugin is vulnerable to it. I was just wondering on an ETA for getting a new version so that we could continue to use the plugin. Right now, it keeps getting disabled because of the vulnerability. All the information I have on it is below: WordPress Library Bookshelves plugin <= 5.8 – Reflected Cross Site Scripting (XSS) vulnerability Reflected Cross Site Scripting (XSS) vulnerability discovered by Mika (Patchstack Alliance) in WordPress Plugin Library Bookshelves (versions <= 5.8) I’m glad you’ve enjoyed using the plugin. An update to fix this vulnerability is in progress. I can’t give you an ETA at this point, but I hope to get around to finishing an update soon. The XSS vulnerability has been patched in version 5.9.

Comments

2 shown
photonicgnostic 2024-11-20T00:54:00+00:00

I’m glad you’ve enjoyed using the plugin. An update to fix this vulnerability is in progress. I can’t give you an ETA at this point, but I hope to get around to finishing an update soon.

photonicgnostic 2024-12-09T01:30:00+00:00

The XSS vulnerability has been patched in version 5.9.