WPIntell

Source evidence

Security compromised

Download Attachments · support · 2025-06-26T09:57:00+00:00

complaintsentiment
highseverity
1.0relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 35 rows with source links

20.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
nicubunu unresolved
Our hosting reported this plugin is vulnerable and asked us to disable/replace it immediately. Info about vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2025-49995 Any plans for an update to fix it? We’ve been reported this. Thing is it’s not a security issue but a plugin feature that can be easilly changed with one option that exists in the plugin. It’s about downloading an attachment by numeric id. We’ve explained them that that is a core plugin feature, but if you don’t like it this way and there is an option to switch from numeric to unique encrypted id (which can’t be identified). They ignored these explanations – did not reply to our email and marked the plugin as having security issues. This is on a couple of government websites, we aren’t allowed to run software with open CVEs. I will have to remove the plugin and maybe look for an alternative.

Comments

2 shown
dFactory 2025-07-01T21:09:00+00:00

We’ve been reported this. Thing is it’s not a security issue but a plugin feature that can be easilly changed with one option that exists in the plugin. It’s about downloading an attachment by numeric id. We’ve explained them that that is a core plugin feature, but if you don’t like it this way and there is an option to switch from numeric to unique encrypted id (which can’t be identified). They ignored these explanations – did not reply to our email and marked the plugin as having security issues.

nicubunu 2025-07-02T07:01:00+00:00

This is on a couple of government websites, we aren’t allowed to run software with open CVEs. I will have to remove the plugin and maybe look for an alternative.