WPIntell

Source evidence

Mend Bolt – Security Issue

JWT Authentication for WP REST API · support · 2025-02-05T16:09:00+00:00

complaintsentiment
highseverity
0.85relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 33 rows with source links

12.1% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Lachezar Gadzhev unresolved
Our project is experiencing a security vulnerability due to this plugin. Could you please release a new version that addresses this issue? Vulnerable Library - ws-7.5.9.tgz Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js Library home page: https://registry.npmjs.org/ws/-/ws-7.5.9.tgz Path to dependency file: /wp-content/plugins/jwt-authentication-for-wp-rest-api/admin/ui/package.json Path to vulnerable library: /wp-content/plugins/jwt-authentication-for-wp-rest-api/admin/ui/package.json Dependency Hierarchy: core-data-6.18.0.tgz (Root Library) sync-0.3.0.tgz y-webrtc-10.2.5.tgz ❌ ws-7.5.9.tgz (Vulnerable Library) Vulnerable Library - path-to-regexp-6.2.1.tgz Express style path to RegExp utility Library home page: https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-6.2.1.tgz Path to dependency file: /wp-content/plugins/jwt-authentication-for-wp-rest-api/admin/ui/package.json Path to vulnerable library: /wp-content/plugins/jwt-authentication-for-wp-rest-api/admin/ui/package.json Dependency Hierarchy: components-25.7.0.tgz (Root Library) ❌ path-to-regexp-6.2.1.tgz (Vulnerable Library) This topic was modified 1 year, 3 months ago by Lachezar Gadzhev . As a patch I can suggest updating this jwt-authentication-for-wp-rest-api/admin/ui/package.json#L23 "@wordpress/core-data": "^6.18.0", to this "@wordpress/core-data": "^6.19.0",

Comments

1 shown
Lachezar Gadzhev 2025-02-07T14:04:00+00:00

As a patch I can suggest updating this jwt-authentication-for-wp-rest-api/admin/ui/package.json#L23 "@wordpress/core-data": "^6.18.0", to this "@wordpress/core-data": "^6.19.0",