WPIntell

Source evidence

security vulnerability

Quantity Plus Minus Button for WooCommerce · support · 2023-12-08T03:52:00+00:00

mixedsentiment
highseverity
0.94relevance
5replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 34 rows with source links

17.6% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
c4concepts resolved
Hi, This plugin is being flagged as having a security vulnerability flagged by Wordfence Security. Are you aware and is there an update coming soon to resolve this issue? Many thanks. Also, in Jetpack Protect: The Quantity Plus Minus Button for WooCommerce by CodeAstrology plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the wqpmb_form_submit function. This makes it possible for unauthenticated attackers to update the plugin’s options via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Any clue? Thanks for informing us. We will check and fix it in next update. Thanks Is the next update planned urgently. I’m considering my options to remove and replace the plugin in several sites as I can’t have them running with known vulnerabilities, but that is a time-consuming process, so I’m hoping the ‘Update Available’ notice appears in my sites admin very soon? Cheers Today I will check out it. Hello @cesarmarti and @c4concepts I have added Nonce verification for form. Please update your plugin.

Comments

5 shown
Estudi Grafema 2023-12-12T09:18:00+00:00

Also, in Jetpack Protect: The Quantity Plus Minus Button for WooCommerce by CodeAstrology plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the wqpmb_form_submit function. This makes it possible for unauthenticated attackers to update the plugin’s options via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Any clue?

Saiful Islam 2023-12-12T14:47:00+00:00

Thanks for informing us. We will check and fix it in next update. Thanks

c4concepts 2023-12-13T00:02:00+00:00

Is the next update planned urgently. I’m considering my options to remove and replace the plugin in several sites as I can’t have them running with known vulnerabilities, but that is a time-consuming process, so I’m hoping the ‘Update Available’ notice appears in my sites admin very soon? Cheers

Saiful Islam 2023-12-13T01:21:00+00:00

Today I will check out it.

Saiful Islam 2023-12-13T07:55:00+00:00

Hello @cesarmarti and @c4concepts I have added Nonce verification for form. Please update your plugin.