WPIntell

Source evidence

CSG – Vulnerable?!

Companion Sitemap Generator – Simple, Smart, and SEO-Ready · support · 2023-03-05T06:27:00+00:00

neutralsentiment
highseverity
0.63relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 34 rows with source links

14.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
rpp resolved
Is something planned to fix the problem? Reported from https://www.wordfence.com/threat-intel/vulnerabilities/id/ccf0d482-b4a1-47a8-8741-0970531e9630 To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Companion Sitemap Generator” until a patched version is available Unfortunately we still haven’t received an answer as to whether a patch is being worked on or not. Too bad actually. Hi, any update on a fix ? I’m about to remove the plugin. Too risky… Hi, bit late with the fix but it’s been fixed in version 4.5.2 @papin I appreciate the update, but it comes a bit too late. My clients’ and I couldn’t wait over a month, (knowing you were notified before the public publishing) for a response to a security vulnerability and have replaced your plugin. Sorry.

Comments

4 shown
rpp 2023-03-18T07:25:00+00:00

Unfortunately we still haven’t received an answer as to whether a patch is being worked on or not. Too bad actually.

morkibut 2023-03-24T12:43:00+00:00

Hi, any update on a fix ? I’m about to remove the plugin. Too risky…

Papin Schipper 2023-03-31T10:36:00+00:00

Hi, bit late with the fix but it’s been fixed in version 4.5.2

Ken Sim 2023-03-31T15:20:00+00:00

@papin I appreciate the update, but it comes a bit too late. My clients’ and I couldn’t wait over a month, (knowing you were notified before the public publishing) for a response to a security vulnerability and have replaced your plugin. Sorry.