WPIntell

Source evidence

Plugin Vulnerability

Worth The Read · support · 2023-03-30T17:58:00+00:00

mixedsentiment
highseverity
0.95relevance
6replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 25 rows with source links

24.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

19 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
T.McGuire resolved
This plugin was reported today as having a Cross Site Request Forgery (CSRF). Would you please check into it so I can safely install it? You can read more about it here: https://ithemes.com/blog/wordpress-vulnerability-report-march-29-2023/ I was not aware of this, thank you for bringing it to my attention. I will look into the issue and have a fix in the next update. Any update on this? It’s still not patched: https://www.wordfence.com/threat-intel/vulnerabilities/detail/appsero-121-missing-authorization?q=worth Doesn’t look like it. The last update to the plugin was 4 months ago with no update since. Not yet, still on the docket. Thanks for your patience! 1.14.1 fixes the vulnerability issue. Thanks for your patience! lol, after checking it every day for 3 months, I deleted it just yesterday because it was completely deleted from the repository.

Comments

6 shown
brianmcculloh 2023-03-31T13:59:00+00:00

I was not aware of this, thank you for bringing it to my attention. I will look into the issue and have a fix in the next update.

maxidavis 2023-05-05T13:56:00+00:00

Any update on this? It’s still not patched: https://www.wordfence.com/threat-intel/vulnerabilities/detail/appsero-121-missing-authorization?q=worth

T.McGuire 2023-05-05T16:53:00+00:00

Doesn’t look like it. The last update to the plugin was 4 months ago with no update since.

brianmcculloh 2023-05-05T18:00:00+00:00

Not yet, still on the docket. Thanks for your patience!

brianmcculloh 2023-08-04T12:48:00+00:00

1.14.1 fixes the vulnerability issue. Thanks for your patience!

maxidavis 2023-08-04T14:43:00+00:00

lol, after checking it every day for 3 months, I deleted it just yesterday because it was completely deleted from the repository.