WPIntell

Source evidence

Email before download possible vulnerability

Email Before Download · support · 2024-02-13T22:40:00+00:00

complaintsentiment
highseverity
1.0relevance
7replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 34 rows with source links

17.6% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
itmonitor unresolved
Hello, where can I post or send information about a potential vulnerability of the plugin Email Before Download? Thanks. Thank you for bringing this to our attention. We are working to resolve this issue. Hi Some news about this issue ? Hi Thanks to keep us informed about this vulnerability. When will you deliver an update ? Hello, We investigated the vulnerability issue and are complying with all of the wordpress standards. Our plugin is built on top of the CF7 form, so mentioning these vulnerabilities to them as well may be beneficial. The vulnerabilities that were linked were provided from a 3rd party website we do not have full access to. If you have more information about this vulnerability and want to collaborate please let us know. Our initial investigation turned up no vulnerabilties on our side of the application. Hello Thanks for your answer. WordFence says “The Plugin Email Before Download has a security vulnerability”. More details here : https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-before-download/email-before-download-697-cross-site-request-forgery Hope it’s help. Hi @want2 , Do you have anything more specific? Our previous comments were based on this vulnerability. After review we did not find any missing or incorrect nonce validation. Thanks, The Email Before Download plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.9.7. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. https://patchstack.com/database/vulnerability/email-before-download/wordpress-email-before-download-plugin-6-9-7-cross-site-request-forgery-csrf-vulnerability Cross Site Request Forgery (CSRF) This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication.

Comments

7 shown
mandsconsulting 2024-02-14T16:58:00+00:00

Thank you for bringing this to our attention. We are working to resolve this issue.

want2 2024-03-11T22:52:00+00:00

Hi Some news about this issue ?

want2 2024-03-27T17:44:00+00:00

Hi Thanks to keep us informed about this vulnerability. When will you deliver an update ?

mandsconsulting 2024-04-23T15:43:00+00:00

Hello, We investigated the vulnerability issue and are complying with all of the wordpress standards. Our plugin is built on top of the CF7 form, so mentioning these vulnerabilities to them as well may be beneficial. The vulnerabilities that were linked were provided from a 3rd party website we do not have full access to. If you have more information about this vulnerability and want to collaborate please let us know. Our initial investigation turned up no vulnerabilties on our side of the application.

want2 2024-04-23T23:26:00+00:00

Hello Thanks for your answer. WordFence says “The Plugin Email Before Download has a security vulnerability”. More details here : https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-before-download/email-before-download-697-cross-site-request-forgery Hope it’s help.

mandsconsulting 2024-04-24T12:34:00+00:00

Hi @want2 , Do you have anything more specific? Our previous comments were based on this vulnerability. After review we did not find any missing or incorrect nonce validation. Thanks,

Jason Hecht 2024-04-27T23:33:00+00:00

The Email Before Download plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.9.7. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. https://patchstack.com/database/vulnerability/email-before-download/wordpress-email-before-download-plugin-6-9-7-cross-site-request-forgery-csrf-vulnerability Cross Site Request Forgery (CSRF) This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication.