WPIntell

Source evidence

Race Condition vulnerability discovered

WPS Limit Login · support · 2023-07-30T14:16:00+00:00

complaintsentiment
highseverity
1.0relevance
15replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 32 rows with source links

18.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
webartist00 unresolved
Hi there, I am using your plugin on several sites. Unfortunately now I get Messages that a vulnerability has discovered. “WPS Limit Login v1.5.6 Low Race Condition vulnerability discovered by konagash (Patchstack Alliance) in WordPress Plugin WPS Limit Login (versions <= 1.5.6)” Will that me solved within the next patch? Yes? When will the next update be launched? Thank you very much in advance! Kind regards, Thomas Same applies to me. Following thread. Hello, Thanks for using WPS Limit Login. Our dev team is working on a patch. We hope we’ll find a patch and release a new version very soon. If you get a way to solve this vulnerability, we’ll be happy to check it 🙂 Thanks. Can you please inform me here as soon as the problem is solved. Thank you very much! @seinomedia If your developer is struggling to find fix perhaps you can share more details on what the race condition is and we in the community can take a closer look. I might be able to spend an hour or two looking at it but I would like a little more direction on how to reproduce or otherwise get pointed out in the right direction before I commit some time. Thanks @shaunek A “race condition” happens when multiple processes or threads access shared resources or data simultaneously, and the outcome is dependent on the order in which these processes execute. You’ve released an update, but the same critical vulnerability exists! Indeed, the update hasn’t fixed it on my end as well. Hello, This issue doens’t exist anymore since the last release. Can you check it, please ? Hello Max – already have checked it, sadly the issue still exists in the version 1.5.7. Yes – it’s still there, according to Wordfence. Hello, Wordfence, database isn’t up to date. This issue has been fixed. The last release has been validated by Patchstack : https://patchstack.com/database @seinomedia Thanks for sharing and thanks for resolving for us. As a side note it is kinda weird that the vuln report doesn’t even exist on Patchstack anymore. When I search for “WPS Limit Login” I get 1 result from 2019 but not the vuln discussed in this thread. But I do see that the Wordfence page links to a no-longer-working page on Patchstack ( https://patchstack.com/database/vulnerability/wps-limit-login/wordpress-wps-limit-login-plugin-1-5-6-race-condition-vulnerability ). Odd that the Patchstack page does a redirect and it isn’t searchable any longer. I will re-install once Wordfence says it is safe to do so. Hi, sorry for my delayed response! On my end, the vulnerable warning in Wordfence is still appearing. @strettonbull , is it working for you, or is it also still showing in Wordfence? No? What have you done to achieve that? Kind regards. It’s still showing in Wordfence.

Comments

15 shown
strettonbull 2023-07-31T15:04:00+00:00

Same applies to me. Following thread.

MaximeWPS 2023-08-02T14:41:00+00:00

Hello, Thanks for using WPS Limit Login. Our dev team is working on a patch. We hope we’ll find a patch and release a new version very soon. If you get a way to solve this vulnerability, we’ll be happy to check it 🙂

webartist00 2023-08-02T19:51:00+00:00

Thanks. Can you please inform me here as soon as the problem is solved. Thank you very much!

shaunek 2023-08-03T18:52:00+00:00

@seinomedia If your developer is struggling to find fix perhaps you can share more details on what the race condition is and we in the community can take a closer look. I might be able to spend an hour or two looking at it but I would like a little more direction on how to reproduce or otherwise get pointed out in the right direction before I commit some time.

MaximeWPS 2023-08-04T08:08:00+00:00

Thanks @shaunek A “race condition” happens when multiple processes or threads access shared resources or data simultaneously, and the outcome is dependent on the order in which these processes execute.

strettonbull 2023-08-27T10:21:00+00:00

You’ve released an update, but the same critical vulnerability exists!

webartist00 2023-08-27T12:28:00+00:00

Indeed, the update hasn’t fixed it on my end as well.

MaximeWPS 2023-09-04T08:15:00+00:00

Hello, This issue doens’t exist anymore since the last release. Can you check it, please ?

webartist00 2023-09-04T10:37:00+00:00

Hello Max – already have checked it, sadly the issue still exists in the version 1.5.7.

strettonbull 2023-09-04T12:07:00+00:00

Yes – it’s still there, according to Wordfence.

MaximeWPS 2023-09-05T07:23:00+00:00

Hello, Wordfence, database isn’t up to date. This issue has been fixed. The last release has been validated by Patchstack : https://patchstack.com/database

shaunek 2023-09-08T22:09:00+00:00

@seinomedia Thanks for sharing and thanks for resolving for us. As a side note it is kinda weird that the vuln report doesn’t even exist on Patchstack anymore. When I search for “WPS Limit Login” I get 1 result from 2019 but not the vuln discussed in this thread. But I do see that the Wordfence page links to a no-longer-working page on Patchstack ( https://patchstack.com/database/vulnerability/wps-limit-login/wordpress-wps-limit-login-plugin-1-5-6-race-condition-vulnerability ). Odd that the Patchstack page does a redirect and it isn’t searchable any longer.

strettonbull 2023-09-09T14:07:00+00:00

I will re-install once Wordfence says it is safe to do so.

webartist00 2024-01-10T17:24:00+00:00

Hi, sorry for my delayed response! On my end, the vulnerable warning in Wordfence is still appearing. @strettonbull , is it working for you, or is it also still showing in Wordfence? No? What have you done to achieve that? Kind regards.

strettonbull 2024-01-11T10:09:00+00:00

It’s still showing in Wordfence.