WPIntell

Source evidence

Security vulnerability.

Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls · support · 2023-12-13T17:51:00+00:00

complaintsentiment
highseverity
1.0relevance
5replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 34 rows with source links

17.6% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Xavier Serrano unresolved
wordfence has notify us of a security vulnerability with this plugin https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/powr-pack/powr-pack-210-authenticated-contributor-stored-cross-site-scripting-via-shortcode The page I need help with: [ log in to see the link] This is still an issue and being reported in email alerts from Solid Security (formerly iThemes Security) twice a day for some time now. I hope that @powr will please take a look at this. It’s never fun to tell a client that they need to find a replacement plugin for one that they have relied on for so long. The latest version 2.2.1 of a plugin don’t have any issues: https://wordpress.org/plugins/powr-pack and patchstack alerts are about version 2.1.0. That is a bit confusing, since the version at https://wordpress.org/plugins/powr-pack/ is still 2.1.0 and there appears to be no 2.2.1 update available at https://wordpress.org/plugins/powr-pack/ nor with the WordPress Dashboard > Plugins section of websites running 2.1.0 Is 2.2.1 only available via special means? Good to see 2.2.1 is now in the repository and scans clean now. Thanks devs. While I can’t speak on behalf of the OP, this should probably be marked as Resolved since the new POWR version 2.2.1 fixes the issue.

Comments

5 shown
anotherdave 2023-12-20T02:26:00+00:00

This is still an issue and being reported in email alerts from Solid Security (formerly iThemes Security) twice a day for some time now. I hope that @powr will please take a look at this. It’s never fun to tell a client that they need to find a replacement plugin for one that they have relied on for so long.

powrranger 2024-01-05T06:51:00+00:00

The latest version 2.2.1 of a plugin don’t have any issues: https://wordpress.org/plugins/powr-pack and patchstack alerts are about version 2.1.0.

anotherdave 2024-01-05T08:02:00+00:00

That is a bit confusing, since the version at https://wordpress.org/plugins/powr-pack/ is still 2.1.0 and there appears to be no 2.2.1 update available at https://wordpress.org/plugins/powr-pack/ nor with the WordPress Dashboard > Plugins section of websites running 2.1.0 Is 2.2.1 only available via special means?

anotherdave 2024-01-09T19:38:00+00:00

Good to see 2.2.1 is now in the repository and scans clean now. Thanks devs.

anotherdave 2024-01-15T06:54:00+00:00

While I can’t speak on behalf of the OP, this should probably be marked as Resolved since the new POWR version 2.2.1 fixes the issue.