WPIntell

Source evidence

Security Vulnerability

Hide admin notices – Admin Notification Center · support · 2023-09-12T01:28:00+00:00

mixedsentiment
highseverity
0.94relevance
5replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

3 / 31 rows with source links

9.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
thirstyjon resolved
This plugin is on an IThemes list of plugins with unpatched vulnerabilities. https://ithemes.com/blog/wordpress-vulnerability-report-september-6-2023/#vulnerability-14035 Does anybody know if this has been patched yet? Hi, Sorry about that, this issue vulnerability has not been fixed. I’ll will make a fix ASAP. Hi, I’ve just released a new version with the fix. Let me know if you need any information 🙂 I just got an email from ithemes this morning saying it is not patched yet. I don’t really know how things work between plug-in developers and security tools like ithemes. Does this mean they have not accepted your patch or that they have not been notified yet? Hi, I’ve uploaded the patch version on the website that reported the vulnerability and it has been accepted. Here is the link: https://patchstack.com/database/vulnerability/wp-admin-notification-center/wordpress-hide-admin-notices-admin-notification-center-plugin-2-3-2-cross-site-request-forgery-csrf-vulnerability I’ve tried to search on itheme where I can contact them for that but there is no information about that. @roumi I’m guessing the info will filter to IThemes eventually. I don’t really know how that works. Thanks for patching that though.

Comments

5 shown
roumi 2023-09-12T06:41:00+00:00

Hi, Sorry about that, this issue vulnerability has not been fixed. I’ll will make a fix ASAP.

roumi 2023-09-12T22:58:00+00:00

Hi, I’ve just released a new version with the fix. Let me know if you need any information 🙂

thirstyjon 2023-09-13T15:40:00+00:00

I just got an email from ithemes this morning saying it is not patched yet. I don’t really know how things work between plug-in developers and security tools like ithemes. Does this mean they have not accepted your patch or that they have not been notified yet?

roumi 2023-09-14T07:11:00+00:00

Hi, I’ve uploaded the patch version on the website that reported the vulnerability and it has been accepted. Here is the link: https://patchstack.com/database/vulnerability/wp-admin-notification-center/wordpress-hide-admin-notices-admin-notification-center-plugin-2-3-2-cross-site-request-forgery-csrf-vulnerability I’ve tried to search on itheme where I can contact them for that but there is no information about that.

thirstyjon 2023-09-19T02:43:00+00:00

@roumi I’m guessing the info will filter to IThemes eventually. I don’t really know how that works. Thanks for patching that though.