Conversation
supportTwo days ago, Patchstack posted a Cross Site Scripting (XSS) vulnerability for this plugin:( https://patchstack.com/database/wordpress/plugin/ditty-news-ticker/vulnerability/wordpress-ditty-plugin-3-1-58-cross-site-scripting-xss-vulnerability?_a_id=350 ). Is there a patch coming from this?
Yes, it would be great if we could have a patch for this also. Many Thanks
Thanks for letting me know about this. For some reason I never received a notification on this issue so I am checking with Patchstack to get more details. As soon as I find out more and resolve the issue I will post an update.
Following
I was able to track down the patchstack notice and the issue listed was already fixed in version 3.1.58. I have resubmitted the update to patchstack so hopefully they close out the notice soon. They previously confirmed with me that it was closed, but for some reason it’s still open.
Sounds good, thanks for the quick update!
I released another small update to ensure this issue was resolved. Please update to version 3.1.59 when you get a chance.
Hi @joemc , thank you for fixing this. I can now confirm that the warning has disappeared from Wordfence too after updating to 3.1.59.
@mikii thanks for letting me know!
Yes, it would be great if we could have a patch for this also. Many Thanks
Thanks for letting me know about this. For some reason I never received a notification on this issue so I am checking with Patchstack to get more details. As soon as I find out more and resolve the issue I will post an update.
Following
I was able to track down the patchstack notice and the issue listed was already fixed in version 3.1.58. I have resubmitted the update to patchstack so hopefully they close out the notice soon. They previously confirmed with me that it was closed, but for some reason it’s still open.
Sounds good, thanks for the quick update!
I released another small update to ensure this issue was resolved. Please update to version 3.1.59 when you get a chance.
Hi @joemc , thank you for fixing this. I can now confirm that the warning has disappeared from Wordfence too after updating to 3.1.59.
@mikii thanks for letting me know!