Conversation
supportChecking if there’s a roadmap for patching this vulnerability: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/connect-daily-web-calendar/wordpress-events-calendar-plugin-connectdaily-154-authenticated-contributor-stored-cross-site-scripting
Yes, we’ll be fixing it in the next couple of weeks. It’s a very low risk bug. The “bug bounty” firm that reported this is difficult to work with and I’ve gone through two iterations already to address it. They don’t respond to emails, and when they do it’s usually copy/pasted without actually responding to the asked questions. They finally communicated what the issue was in a specific way about a week ago.
I’ve pushed up a new release that fixes the issues they communicated to me. I’ve provided the reporting company with a patch so they can vet the changes.
The reporter shows this issue as resolved.
Yes, we’ll be fixing it in the next couple of weeks. It’s a very low risk bug. The “bug bounty” firm that reported this is difficult to work with and I’ve gone through two iterations already to address it. They don’t respond to emails, and when they do it’s usually copy/pasted without actually responding to the asked questions. They finally communicated what the issue was in a specific way about a week ago.
I’ve pushed up a new release that fixes the issues they communicated to me. I’ve provided the reporting company with a patch so they can vet the changes.
The reporter shows this issue as resolved.