WPIntell

Source evidence

vulnerability alert

Advanced WordPress Backgrounds · support · 2025-12-08T15:10:00+00:00

mixedsentiment
highseverity
0.88relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 27 rows with source links

18.5% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

22 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Mathilde Rivoire resolved
I received a vulnerability alert: Advanced WordPress Backgrounds <= 1.12.7 – Authenticated (Contributor+) Content Injection Have you planned a patch? +1 Looks like all of my sites disabled jarallax since the the last 6.9 WP update. I’ve manually enqueued and hosted the files myself on some sites, but a patch to this plugin would be nice. Hi @mathilde-rivoire The plugin has no vulnerability. WPScan has not removed the false alert and is ignoring our emails. Please learn more here → https://wordpress.org/support/topic/security-issue-175/ Regards, Nikita. ok, thanks for your response !

Comments

3 shown
mapples 2025-12-10T04:42:00+00:00

+1 Looks like all of my sites disabled jarallax since the the last 6.9 WP update. I’ve manually enqueued and hosted the files myself on some sites, but a patch to this plugin would be nice.

nK 2025-12-10T06:03:00+00:00

Hi @mathilde-rivoire The plugin has no vulnerability. WPScan has not removed the false alert and is ignoring our emails. Please learn more here → https://wordpress.org/support/topic/security-issue-175/ Regards, Nikita.

Mathilde Rivoire 2025-12-10T08:39:00+00:00

ok, thanks for your response !