WPIntell

Source evidence

False positive for plugin vulnerability?

Jetpack Protect · support · 2025-04-01T16:22:00+00:00

mixedsentiment
highseverity
0.94relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 32 rows with source links

18.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Boone Gorges resolved
I’m one of the authors of the BuddyPress Docs plugin https://wordpress.org/plugins/buddypress-docs/ and I received a user report that Jetpack Protect is reporting that the latest version of the plugin has “a known security vulnerability”. Your AI support bot said that you use WP Scan’s vulnerability database, but I don’t see any public, pending vulnerabilities there. I haven’t received any private communication from your team, or from WP Scan, or from other reporters. Could someone on your team please have a look, and follow up privately if there’s a non-public vulnerability that for some reason has not been reported to me? Thanks in advance for your help. Hi there, There is a publicly known vulnerability for your plugin published by Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress-docs/ , which is related to Reflected XSS in v2.2.3. However it seems like you fixed it in the latest version (2.2.4) but Wordfence did not update their database about it somehow. ​I’ve updated the advisory on our side ( https://wpscan.com/plugin/buddypress-docs/ ), and that should solve the issue in Jetpack Protect, however you should also contact Wordfence to have them update their database. Hi @erwanlr – Thank you so much for the quick response and for straightening this out on the Jetpack end. I’ll reach out to Wordfence.

Comments

2 shown
Erwan Le Rousseau 2025-04-02T08:22:00+00:00

Hi there, There is a publicly known vulnerability for your plugin published by Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/buddypress-docs/ , which is related to Reflected XSS in v2.2.3. However it seems like you fixed it in the latest version (2.2.4) but Wordfence did not update their database about it somehow. ​I’ve updated the advisory on our side ( https://wpscan.com/plugin/buddypress-docs/ ), and that should solve the issue in Jetpack Protect, however you should also contact Wordfence to have them update their database.

Boone Gorges 2025-04-03T16:13:00+00:00

Hi @erwanlr – Thank you so much for the quick response and for straightening this out on the Jetpack end. I’ll reach out to Wordfence.