Conversation
supportPatchstack reports that the latest version (0.9.1) is still vulnerable: https://patchstack.com/database/wordpress/plugin/link-whisper/vulnerability/wordpress-link-whisper-free-plugin-0-9-0-reflected-cross-site-scripting-xss-vulnerability
Hey Chris, Thanks for pointing that out and for sharing the Patchstack link. I’ve released a fix for the vulnerability in the 0.9.2 update of Link Whisper Free . If you update to that version, the issue should be resolved. It may take a day or two for Patchstack to review and verify the fix on their end, so their database may still show the previous status for a short time. But the patch is already included in the latest update. Appreciate you bringing it up. Warm regards, Matt
Thanks for the update! Chris
Hi Matt, Are you aware that Patchstack is still listing the plugin as vulnerable, up to and including the latest version? WordPress Link Whisper Free Plugin <= 0.9.2 is vulnerable to a medium priority Cross Site Scripting (XSS) https://patchstack.com/database/wordpress/plugin/link-whisper/vulnerability/wordpress-link-whisper-free-plugin-0-9-0-reflected-cross-site-scripting-xss-vulnerability
Hey Chris, Thanks for pointing that out and for sharing the Patchstack link. I’ve released a fix for the vulnerability in the 0.9.2 update of Link Whisper Free . If you update to that version, the issue should be resolved. It may take a day or two for Patchstack to review and verify the fix on their end, so their database may still show the previous status for a short time. But the patch is already included in the latest update. Appreciate you bringing it up. Warm regards, Matt
Thanks for the update! Chris
Hi Matt, Are you aware that Patchstack is still listing the plugin as vulnerable, up to and including the latest version? WordPress Link Whisper Free Plugin <= 0.9.2 is vulnerable to a medium priority Cross Site Scripting (XSS) https://patchstack.com/database/wordpress/plugin/link-whisper/vulnerability/wordpress-link-whisper-free-plugin-0-9-0-reflected-cross-site-scripting-xss-vulnerability