Conversation
supportI received a vulnerability alert: Advanced WordPress Backgrounds <= 1.12.7 – Authenticated (Contributor+) Content Injection Have you planned a patch?
+1 Looks like all of my sites disabled jarallax since the the last 6.9 WP update. I’ve manually enqueued and hosted the files myself on some sites, but a patch to this plugin would be nice.
Hi @mathilde-rivoire The plugin has no vulnerability. WPScan has not removed the false alert and is ignoring our emails. Please learn more here → https://wordpress.org/support/topic/security-issue-175/ Regards, Nikita.
ok, thanks for your response !
+1 Looks like all of my sites disabled jarallax since the the last 6.9 WP update. I’ve manually enqueued and hosted the files myself on some sites, but a patch to this plugin would be nice.
Hi @mathilde-rivoire The plugin has no vulnerability. WPScan has not removed the false alert and is ignoring our emails. Please learn more here → https://wordpress.org/support/topic/security-issue-175/ Regards, Nikita.
ok, thanks for your response !