WPIntell

Source evidence

Vulnerability?

Zapier for WordPress · support · 2025-06-27T11:55:00+00:00

complaintsentiment
highseverity
1.0relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 35 rows with source links

20.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
espressivo unresolved
there seems to be a vulnerability in the plugin, is there a fix coming any time soon? https://patchstack.com/database/wordpress/plugin/zapier/vulnerability/wordpress-zapier-for-wordpress-plugin-1-5-2-broken-access-control-vulnerability?_a_id=350 Circling back to this to check in This was Zapier’s reply when I contacted them directly. You must contact them through the zapier website to report yourself as an affected user. I’ve been checking this and I see that we have an open bug report to handle this vulnerability, so I’ve added your email address as an affected user, which means you’ll be notified once it’s fixed. I see it’s being worked on, but I don’t have an exact timeline for when it will be resolved though. Timing: Our development team prioritizes these types of reports based on overall impact. Thanks @anphira I have noticed that the plugin has been updated, but the update cannot be activated because there is “no header.” I have contacted Zapier as you have recommended. (And I’ve asked them to test it with the most up to date version of WordPress, too!) Mark

Comments

3 shown
espressivo 2025-07-08T12:04:00+00:00

Circling back to this to check in

anphira 2025-07-19T18:30:00+00:00

This was Zapier’s reply when I contacted them directly. You must contact them through the zapier website to report yourself as an affected user. I’ve been checking this and I see that we have an open bug report to handle this vulnerability, so I’ve added your email address as an affected user, which means you’ll be notified once it’s fixed. I see it’s being worked on, but I don’t have an exact timeline for when it will be resolved though. Timing: Our development team prioritizes these types of reports based on overall impact.

revcoincidence 2025-07-28T08:01:00+00:00

Thanks @anphira I have noticed that the plugin has been updated, but the update cannot be activated because there is “no header.” I have contacted Zapier as you have recommended. (And I’ve asked them to test it with the most up to date version of WordPress, too!) Mark