WPIntell

Source evidence

Marked as vulnerable

Widgets on Pages · support · 2023-05-12T07:20:00+00:00

complaintsentiment
highseverity
0.96relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

3 / 32 rows with source links

9.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Three AM Web + IT unresolved
Hey, this plugin has been marked as vulnerable since 17/01/2023 on WPScan and Patchstack. Will this be resolved? The page I need help with: [ log in to see the link] This was resolved in the 1.7 release. I don’t know why those sites have not been updated. Hi Todd, I have asked the Patchstack team and their response was: It’s still vulnerable. The developer used dev used esc_js instead of esc_attr. Please patch it correctly and let us know. We will check the patch and validate it. We are still getting server notifications about this: WordPress Widgets on Pages plugin <= 1.7.0 – Contributor Stored XSS vulnerability Is this going to be patched soon? Hullo, I’m still a bit confused as to why this is marked as such, but I have an update coming soon that might address this. From my side I cannot really see any issues with the current implementation, but I’m trying to harden it even further.

Comments

4 shown
toddhalfpenny 2023-05-12T07:46:00+00:00

This was resolved in the 1.7 release. I don’t know why those sites have not been updated.

Three AM Web + IT 2023-05-15T22:28:00+00:00

Hi Todd, I have asked the Patchstack team and their response was: It’s still vulnerable. The developer used dev used esc_js instead of esc_attr. Please patch it correctly and let us know. We will check the patch and validate it.

ivoryshogun 2023-06-16T20:01:00+00:00

We are still getting server notifications about this: WordPress Widgets on Pages plugin <= 1.7.0 – Contributor Stored XSS vulnerability Is this going to be patched soon?

toddhalfpenny 2023-07-04T08:13:00+00:00

Hullo, I’m still a bit confused as to why this is marked as such, but I have an update coming soon that might address this. From my side I cannot really see any issues with the current implementation, but I’m trying to harden it even further.