Conversation
supportHello, Wordfence shows security issue. https://mallorca-broker.com Worpress 6.9.4 , Theme editor 3.2 Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Theme Editor” until a patched version is available. https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/theme-editor/theme-editor-32-cross-site-request-forgery Hope you can solve the security problem. Regards Rainer The page I need help with: [ log in to see the link]
Yes, I read an article posted by WordFence about this vulnerability a couple of months ago . Is this vulnerability going to be patched in the near future? If not, I’ll need to delete the Theme Editor plugin. Best, Matthew
Hi @rainer-r @matthewjasonklodt , Our team has fixed this vulnerability in Theme Editor plugin. The fix will be shared on the live stage soon. Thanks for the alert. If you have any questions about the fix, please feel free to ask. Regards, WP Theme Editor Support.
Good news 👍
Thanks for your update, @emma1991 . Do you have any ETA regarding the release of this plugin update? This vulnerability has been listed on WordFence’s Intelligence reports for several months now, so I need to make a decision whether or not to disable/remove the ‘Theme Editor’ plugin, at least for the time being, until the security fix has been uploaded. Thanks. Best, Matthew This reply was modified 3 weeks, 2 days ago by Matthew Klodt . Reason: Wanted to include a link to WordFence's report to clarify the issue that I'm referring to
Hi @matthewjasonklodt , We have fixed this issue – please update the plugin to the latest version and check. Let us know if you need any further help! Thanks, Theme Editor Support Team
@emma1991 , where can we find the updated version? There is no update showing in my WordPress admin and the previous plugin version is still listed on the WordPress.org plugin repository. This reply was modified 1 week, 4 days ago by Matthew Klodt .
Hi @matthewjasonklodt , Thank you for your patience! We have a patch ready for you to test. Please download it using the link below and install it manually by going to Plugins → Add New → Upload Plugin : 📎 theme-editor-v-3.3.zip Please check if this resolves the issue and let us know how it goes. We’ll push the official update to the WordPress.org repository shortly. Thanks, Theme Editor Support Team
@emma1991 , That seems to have fixed the security warning in WordFence on my personal WordPress website. I’m not seeing any PHP errors or warnings either related to the ‘Theme Editor’ plugin updator, so it looks good. However, I don’t want to install it on my client’s website until you’re finished testing it and the new version has been uploaded to the WordPress pluginr repository. Next time if you need me to do any plugin testing, you’ll need to hire me for my freelance WordPress development services. 😉
Yes, I read an article posted by WordFence about this vulnerability a couple of months ago . Is this vulnerability going to be patched in the near future? If not, I’ll need to delete the Theme Editor plugin. Best, Matthew
Hi @rainer-r @matthewjasonklodt , Our team has fixed this vulnerability in Theme Editor plugin. The fix will be shared on the live stage soon. Thanks for the alert. If you have any questions about the fix, please feel free to ask. Regards, WP Theme Editor Support.
Good news 👍
Thanks for your update, @emma1991 . Do you have any ETA regarding the release of this plugin update? This vulnerability has been listed on WordFence’s Intelligence reports for several months now, so I need to make a decision whether or not to disable/remove the ‘Theme Editor’ plugin, at least for the time being, until the security fix has been uploaded. Thanks. Best, Matthew This reply was modified 3 weeks, 2 days ago by Matthew Klodt . Reason: Wanted to include a link to WordFence's report to clarify the issue that I'm referring to
Hi @matthewjasonklodt , We have fixed this issue – please update the plugin to the latest version and check. Let us know if you need any further help! Thanks, Theme Editor Support Team
@emma1991 , where can we find the updated version? There is no update showing in my WordPress admin and the previous plugin version is still listed on the WordPress.org plugin repository. This reply was modified 1 week, 4 days ago by Matthew Klodt .
Hi @matthewjasonklodt , Thank you for your patience! We have a patch ready for you to test. Please download it using the link below and install it manually by going to Plugins → Add New → Upload Plugin : 📎 theme-editor-v-3.3.zip Please check if this resolves the issue and let us know how it goes. We’ll push the official update to the WordPress.org repository shortly. Thanks, Theme Editor Support Team
@emma1991 , That seems to have fixed the security warning in WordFence on my personal WordPress website. I’m not seeing any PHP errors or warnings either related to the ‘Theme Editor’ plugin updator, so it looks good. However, I don’t want to install it on my client’s website until you’re finished testing it and the new version has been uploaded to the WordPress pluginr repository. Next time if you need me to do any plugin testing, you’ll need to hire me for my freelance WordPress development services. 😉