Conversation
supportHello, where can I post or send information about a potential vulnerability of the plugin Email Before Download? Thanks.
Thank you for bringing this to our attention. We are working to resolve this issue.
Hi Some news about this issue ?
Hi Thanks to keep us informed about this vulnerability. When will you deliver an update ?
Hello, We investigated the vulnerability issue and are complying with all of the wordpress standards. Our plugin is built on top of the CF7 form, so mentioning these vulnerabilities to them as well may be beneficial. The vulnerabilities that were linked were provided from a 3rd party website we do not have full access to. If you have more information about this vulnerability and want to collaborate please let us know. Our initial investigation turned up no vulnerabilties on our side of the application.
Hello Thanks for your answer. WordFence says “The Plugin Email Before Download has a security vulnerability”. More details here : https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-before-download/email-before-download-697-cross-site-request-forgery Hope it’s help.
Hi @want2 , Do you have anything more specific? Our previous comments were based on this vulnerability. After review we did not find any missing or incorrect nonce validation. Thanks,
The Email Before Download plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.9.7. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. https://patchstack.com/database/vulnerability/email-before-download/wordpress-email-before-download-plugin-6-9-7-cross-site-request-forgery-csrf-vulnerability Cross Site Request Forgery (CSRF) This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication.
Thank you for bringing this to our attention. We are working to resolve this issue.
Hi Some news about this issue ?
Hi Thanks to keep us informed about this vulnerability. When will you deliver an update ?
Hello, We investigated the vulnerability issue and are complying with all of the wordpress standards. Our plugin is built on top of the CF7 form, so mentioning these vulnerabilities to them as well may be beneficial. The vulnerabilities that were linked were provided from a 3rd party website we do not have full access to. If you have more information about this vulnerability and want to collaborate please let us know. Our initial investigation turned up no vulnerabilties on our side of the application.
Hello Thanks for your answer. WordFence says “The Plugin Email Before Download has a security vulnerability”. More details here : https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-before-download/email-before-download-697-cross-site-request-forgery Hope it’s help.
Hi @want2 , Do you have anything more specific? Our previous comments were based on this vulnerability. After review we did not find any missing or incorrect nonce validation. Thanks,
The Email Before Download plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.9.7. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. https://patchstack.com/database/vulnerability/email-before-download/wordpress-email-before-download-plugin-6-9-7-cross-site-request-forgery-csrf-vulnerability Cross Site Request Forgery (CSRF) This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication.