WPIntell

Source evidence

Security Vulnerability

WP Email Template · support · 2025-09-08T15:23:00+00:00

complaintsentiment
highseverity
0.96relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 34 rows with source links

17.6% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
emswpuser unresolved
Patchstack released a report on a WP Email Template plugin security vulnerability. Please let us know when you’ll release a patch. Thank you. The page I need help with: [ log in to see the link] Thanks @emswpuser First I’ve heard of this and I can see why Patchstack has not notified us directly and discreetly as they normally do when a vulnerability is reported. From the Patchstack link you posted, this appears to be a theoretical report as there is no proof-of-concept. The patchstack link you shared states: “ Solutions – This security issue has a low severity impact and is unlikely to be exploited. “ I’ve reviewed the public advisory which currently contains only a generic CSRF classification with that low severity and no proof-of-concept or affected endpoint. I’ve reached out to Patchstack for exact reproduction steps so we can evaluate and, if needed, issue a fix. If you have any additional technical details (endpoint, parameters, required state), please share so we can verify promptly. Steve Hi Steve, Thank you for the quick reply. I don’t have any other information. I hope Patchstack can provide you with further details. Thanks.

Comments

2 shown
Steve Truman 2025-09-08T19:53:00+00:00

Thanks @emswpuser First I’ve heard of this and I can see why Patchstack has not notified us directly and discreetly as they normally do when a vulnerability is reported. From the Patchstack link you posted, this appears to be a theoretical report as there is no proof-of-concept. The patchstack link you shared states: “ Solutions – This security issue has a low severity impact and is unlikely to be exploited. “ I’ve reviewed the public advisory which currently contains only a generic CSRF classification with that low severity and no proof-of-concept or affected endpoint. I’ve reached out to Patchstack for exact reproduction steps so we can evaluate and, if needed, issue a fix. If you have any additional technical details (endpoint, parameters, required state), please share so we can verify promptly. Steve

emswpuser 2025-09-08T21:05:00+00:00

Hi Steve, Thank you for the quick reply. I don’t have any other information. I hope Patchstack can provide you with further details. Thanks.