Conversation
supportwordfence has notify us of a security vulnerability with this plugin https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/powr-pack/powr-pack-210-authenticated-contributor-stored-cross-site-scripting-via-shortcode The page I need help with: [ log in to see the link]
This is still an issue and being reported in email alerts from Solid Security (formerly iThemes Security) twice a day for some time now. I hope that @powr will please take a look at this. It’s never fun to tell a client that they need to find a replacement plugin for one that they have relied on for so long.
The latest version 2.2.1 of a plugin don’t have any issues: https://wordpress.org/plugins/powr-pack and patchstack alerts are about version 2.1.0.
That is a bit confusing, since the version at https://wordpress.org/plugins/powr-pack/ is still 2.1.0 and there appears to be no 2.2.1 update available at https://wordpress.org/plugins/powr-pack/ nor with the WordPress Dashboard > Plugins section of websites running 2.1.0 Is 2.2.1 only available via special means?
Good to see 2.2.1 is now in the repository and scans clean now. Thanks devs.
While I can’t speak on behalf of the OP, this should probably be marked as Resolved since the new POWR version 2.2.1 fixes the issue.
This is still an issue and being reported in email alerts from Solid Security (formerly iThemes Security) twice a day for some time now. I hope that @powr will please take a look at this. It’s never fun to tell a client that they need to find a replacement plugin for one that they have relied on for so long.
The latest version 2.2.1 of a plugin don’t have any issues: https://wordpress.org/plugins/powr-pack and patchstack alerts are about version 2.1.0.
That is a bit confusing, since the version at https://wordpress.org/plugins/powr-pack/ is still 2.1.0 and there appears to be no 2.2.1 update available at https://wordpress.org/plugins/powr-pack/ nor with the WordPress Dashboard > Plugins section of websites running 2.1.0 Is 2.2.1 only available via special means?
Good to see 2.2.1 is now in the repository and scans clean now. Thanks devs.
While I can’t speak on behalf of the OP, this should probably be marked as Resolved since the new POWR version 2.2.1 fixes the issue.