Conversation
supportHello, Plugin Vulnerability Notification by WP Engine : please check below links: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50826 https://patchstack.com/database/vulnerability/menu-image/wordpress-menu-image-icons-made-easy-plugin-3-10-cross-site-scripting-xss-vulnerability https://wpscan.com/vulnerability/469e3568-cb7e-498e-9458-e7952b2ff31f seems like an issue related to Cross Site Scripting(XSS). Please provide a plugin update ASAP.
Hi @welswebmaster and @dishamodi I just got the details of the vulnerability and will provide a fix in the next 24hours.
Hi @welswebmaster and @dishamodi I just released the version 3.11 that fixes this issue. give it a try. I submmited the changes to Patchstack so it will be necessary to wait for their review so that the status can change to patched.
Hi Rui Guerreiro , Sorry to say but the issue is not fixed yet. Please check the screenshot: https://gyazo.com/733d77416dbb9d12415f8224717d7f6c Please fix it ASAP.
Hi @dishamodi It takes time for the situation change, I sent the code to Patchstack and they will have a look and update their database. Only after that the other plugins like Wordfence should check again the vulnerability database.
Hi @welswebmaster and @dishamodi I just got the details of the vulnerability and will provide a fix in the next 24hours.
Hi @welswebmaster and @dishamodi I just released the version 3.11 that fixes this issue. give it a try. I submmited the changes to Patchstack so it will be necessary to wait for their review so that the status can change to patched.
Hi Rui Guerreiro , Sorry to say but the issue is not fixed yet. Please check the screenshot: https://gyazo.com/733d77416dbb9d12415f8224717d7f6c Please fix it ASAP.
Hi @dishamodi It takes time for the situation change, I sent the code to Patchstack and they will have a look and update their database. Only after that the other plugins like Wordfence should check again the vulnerability database.