WPIntell

Source evidence

Plugin Vulnerability

Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News · support · 2024-09-06T06:52:00+00:00

mixedsentiment
highseverity
0.94relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 22 rows with source links

27.3% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

16 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
samch31 resolved
Hello team! I love your plugin, and I recently bought the pro version! I use Wordfence for security scans, and a recent scan confirmed a vulnerability with the plugin. I can see on Wordfence site that there’s a patched version already, but it appears the vulnerability is on the standard plugin: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/blog-designer-pack/news-blog-designer-pack-wordpress-blog-plugin-341-unauthenticated-remote-code-execution My pro version is different. There isn’t an update available, and the version differs to the standard plugin version, of course. But it keeps getting flagged in a Wordfence scan. What should I do? Should I remove your pro plugin for the interim? Or is it being shown in error by Wordfence? Many thanks! Hi @samch31 Thanks for reaching out to us and providing the web page link. I have checked it and Yes, It is a free version which was already updated. Right now there is no vulnerability within the plugin. You can see “Patched” to “Yes” within the provided link. Also it is for Free version. Right now in there is no security vulnerability within the plugin. Also WordPress ORG forum is limited to Free version and its support. If you have any query related to premium version you can reach out to my support. This reply was modified 1 year, 10 months ago by James Huff . This reply was modified 1 year, 10 months ago by pluginandplay . That’s really helpful, thanks so much for your help on this query!

Comments

2 shown
pluginandplay 2024-09-08T07:36:00+00:00

Hi @samch31 Thanks for reaching out to us and providing the web page link. I have checked it and Yes, It is a free version which was already updated. Right now there is no vulnerability within the plugin. You can see “Patched” to “Yes” within the provided link. Also it is for Free version. Right now in there is no security vulnerability within the plugin. Also WordPress ORG forum is limited to Free version and its support. If you have any query related to premium version you can reach out to my support. This reply was modified 1 year, 10 months ago by James Huff . This reply was modified 1 year, 10 months ago by pluginandplay .

samch31 2024-09-09T12:18:00+00:00

That’s really helpful, thanks so much for your help on this query!