Conversation
supportI’m one of the authors of the BuddyPress Docs plugin https://wordpress.org/plugins/buddypress-docs/ and I received a user report that Jetpack Protect is reporting that the latest version of the plugin has “a known security vulnerability”. Your AI support bot said that you use WP Scan’s vulnerability database, but I don’t see any public, pending vulnerabilities there. I haven’t received any private communication from your team, or from WP Scan, or from other reporters. Could someone on your team please have a look, and follow up privately if there’s a non-public vulnerability that for some reason has not been reported to me? Thanks in advance for your help.
Hi there, There is a publicly known vulnerability for your plugin published by Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress-docs/ , which is related to Reflected XSS in v2.2.3. However it seems like you fixed it in the latest version (2.2.4) but Wordfence did not update their database about it somehow. I’ve updated the advisory on our side ( https://wpscan.com/plugin/buddypress-docs/ ), and that should solve the issue in Jetpack Protect, however you should also contact Wordfence to have them update their database.
Hi @erwanlr – Thank you so much for the quick response and for straightening this out on the Jetpack end. I’ll reach out to Wordfence.
Hi there, There is a publicly known vulnerability for your plugin published by Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress-docs/ , which is related to Reflected XSS in v2.2.3. However it seems like you fixed it in the latest version (2.2.4) but Wordfence did not update their database about it somehow. I’ve updated the advisory on our side ( https://wpscan.com/plugin/buddypress-docs/ ), and that should solve the issue in Jetpack Protect, however you should also contact Wordfence to have them update their database.
Hi @erwanlr – Thank you so much for the quick response and for straightening this out on the Jetpack end. I’ll reach out to Wordfence.