Conversation
supportthere seems to be a vulnerability in the plugin, is there a fix coming any time soon? https://patchstack.com/database/wordpress/plugin/zapier/vulnerability/wordpress-zapier-for-wordpress-plugin-1-5-2-broken-access-control-vulnerability?_a_id=350
Circling back to this to check in
This was Zapier’s reply when I contacted them directly. You must contact them through the zapier website to report yourself as an affected user. I’ve been checking this and I see that we have an open bug report to handle this vulnerability, so I’ve added your email address as an affected user, which means you’ll be notified once it’s fixed. I see it’s being worked on, but I don’t have an exact timeline for when it will be resolved though. Timing: Our development team prioritizes these types of reports based on overall impact.
Thanks @anphira I have noticed that the plugin has been updated, but the update cannot be activated because there is “no header.” I have contacted Zapier as you have recommended. (And I’ve asked them to test it with the most up to date version of WordPress, too!) Mark
Circling back to this to check in
This was Zapier’s reply when I contacted them directly. You must contact them through the zapier website to report yourself as an affected user. I’ve been checking this and I see that we have an open bug report to handle this vulnerability, so I’ve added your email address as an affected user, which means you’ll be notified once it’s fixed. I see it’s being worked on, but I don’t have an exact timeline for when it will be resolved though. Timing: Our development team prioritizes these types of reports based on overall impact.
Thanks @anphira I have noticed that the plugin has been updated, but the update cannot be activated because there is “no header.” I have contacted Zapier as you have recommended. (And I’ve asked them to test it with the most up to date version of WordPress, too!) Mark