Conversation
supportOur hosting reported this plugin is vulnerable and asked us to disable/replace it immediately. Info about vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2025-49995 Any plans for an update to fix it?
We’ve been reported this. Thing is it’s not a security issue but a plugin feature that can be easilly changed with one option that exists in the plugin. It’s about downloading an attachment by numeric id. We’ve explained them that that is a core plugin feature, but if you don’t like it this way and there is an option to switch from numeric to unique encrypted id (which can’t be identified). They ignored these explanations – did not reply to our email and marked the plugin as having security issues.
This is on a couple of government websites, we aren’t allowed to run software with open CVEs. I will have to remove the plugin and maybe look for an alternative.
We’ve been reported this. Thing is it’s not a security issue but a plugin feature that can be easilly changed with one option that exists in the plugin. It’s about downloading an attachment by numeric id. We’ve explained them that that is a core plugin feature, but if you don’t like it this way and there is an option to switch from numeric to unique encrypted id (which can’t be identified). They ignored these explanations – did not reply to our email and marked the plugin as having security issues.
This is on a couple of government websites, we aren’t allowed to run software with open CVEs. I will have to remove the plugin and maybe look for an alternative.