WPIntell

Source evidence

Plugin Vulnerability Notification by WP Engine

Menu Image, Icons made easy · support · 2023-12-27T07:02:00+00:00

complaintsentiment
highseverity
0.96relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 32 rows with source links

12.5% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
dishamodi unresolved
Hello, Plugin Vulnerability Notification by WP Engine : please check below links: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50826 https://patchstack.com/database/vulnerability/menu-image/wordpress-menu-image-icons-made-easy-plugin-3-10-cross-site-scripting-xss-vulnerability https://wpscan.com/vulnerability/469e3568-cb7e-498e-9458-e7952b2ff31f seems like an issue related to Cross Site Scripting(XSS). Please provide a plugin update ASAP. Hi @welswebmaster and @dishamodi I just got the details of the vulnerability and will provide a fix in the next 24hours. Hi @welswebmaster and @dishamodi I just released the version 3.11 that fixes this issue. give it a try. I submmited the changes to Patchstack so it will be necessary to wait for their review so that the status can change to patched. Hi Rui Guerreiro , Sorry to say but the issue is not fixed yet. Please check the screenshot: https://gyazo.com/733d77416dbb9d12415f8224717d7f6c Please fix it ASAP. Hi @dishamodi It takes time for the situation change, I sent the code to Patchstack and they will have a look and update their database. Only after that the other plugins like Wordfence should check again the vulnerability database.

Comments

4 shown
Rui Guerreiro 2023-12-27T14:40:00+00:00

Hi @welswebmaster and @dishamodi I just got the details of the vulnerability and will provide a fix in the next 24hours.

Rui Guerreiro 2023-12-27T20:58:00+00:00

Hi @welswebmaster and @dishamodi I just released the version 3.11 that fixes this issue. give it a try. I submmited the changes to Patchstack so it will be necessary to wait for their review so that the status can change to patched.

dishamodi 2023-12-28T12:30:00+00:00

Hi Rui Guerreiro , Sorry to say but the issue is not fixed yet. Please check the screenshot: https://gyazo.com/733d77416dbb9d12415f8224717d7f6c Please fix it ASAP.

Rui Guerreiro 2023-12-28T13:03:00+00:00

Hi @dishamodi It takes time for the situation change, I sent the code to Patchstack and they will have a look and update their database. Only after that the other plugins like Wordfence should check again the vulnerability database.