WPIntell

Source evidence

Vulnerability alerts

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) · support · 2026-04-16T21:26:00+00:00

mixedsentiment
highseverity
0.95relevance
7replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 32 rows with source links

18.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
executekone resolved
Hello, Today I received two vulnerability alerts, but both appear to relate to older issues. One of them has already been fixed in my setup, and the other currently does not have an available fix. Could you please explain why I received both notifications today, even though I haven’t made any changes to my setup? I would also appreciate guidance on how I should handle both alerts going forward. The flagged issues are: https://vulnerabilities.really-simple-security.com/plugin/wp-staging/2cd666db-2064-49d2-82a8-b54d9b3173e5/ https://vulnerabilities.really-simple-security.com/core/wordpress/5ced61db-91b4-4f32-8ec5-aa4038e425e3/ Best, Daniel Hi @executekone , You may have seen two WordPress Core issues being flagged recently. An oversight in how our Vulnerabilities API classified these particular entries caused them to show up much more broadly than they were originally intended to. These issues should’ve behaved differently from ‘standard’ vulnerabilities; since there’s no practical “fixed version” of WordPress Core that you could install to make this risk go away, and exploitation of these two issues is considered highly unlikely without the presence of additional weaknesses. We’ve corrected the API so these (and similar cases) are handled as we intended once more, and once your site syncs the updated vulnerability data, these WordPress Core notices should be cleared accordingly. Please note that syncing will happen automatically, but this may take a short time and will not happen instantly on every site. As for the WP Staging plugin, if you’ve already updated to a patched version of that plugin; the notice about that should disappear as well after some time passes. If this does not happen, could you let me know which version of the WP Staging plugin you’re using (and whether this concerns the Free or Pro version)? Kind regards, Jarno Hi @jarnovos , Thank you for the detailed answer. I am using WP Staging already for some time, but the vulnerability alert occurred yesterday. I am currently using the free version 4.7.3. Kind regards, Daniel Hi @executekone , Appreciate the quick update here, I have taken a look at our data for the WP Staging plugin as well. I can confirm that the notification was a false positive as WP Staging (Free) 4.7.3 is not vulnerable to this issue. The short summary is that the alert fired as our system treated WP Staging Free like the Pro one for the version comparison. We’ve corrected this on our end already, so once your site re-syncs the new vulnerability data (~1 day), this warning should automatically disappear as a result. Thanks again for letting us know about this. Kind regards, Jarno Thank you very much. Hi @jarnovos , my site still shows WP Staging as vulnerable. It is now resolved. Thank you. Hi @executekone , Thanks a lot for confirming the solution, much appreciated. Kind regards, Jarno

Comments

7 shown
Jarno Vos 2026-04-17T08:47:00+00:00

Hi @executekone , You may have seen two WordPress Core issues being flagged recently. An oversight in how our Vulnerabilities API classified these particular entries caused them to show up much more broadly than they were originally intended to. These issues should’ve behaved differently from ‘standard’ vulnerabilities; since there’s no practical “fixed version” of WordPress Core that you could install to make this risk go away, and exploitation of these two issues is considered highly unlikely without the presence of additional weaknesses. We’ve corrected the API so these (and similar cases) are handled as we intended once more, and once your site syncs the updated vulnerability data, these WordPress Core notices should be cleared accordingly. Please note that syncing will happen automatically, but this may take a short time and will not happen instantly on every site. As for the WP Staging plugin, if you’ve already updated to a patched version of that plugin; the notice about that should disappear as well after some time passes. If this does not happen, could you let me know which version of the WP Staging plugin you’re using (and whether this concerns the Free or Pro version)? Kind regards, Jarno

executekone 2026-04-17T12:42:00+00:00

Hi @jarnovos , Thank you for the detailed answer. I am using WP Staging already for some time, but the vulnerability alert occurred yesterday. I am currently using the free version 4.7.3. Kind regards, Daniel

Jarno Vos 2026-04-17T13:49:00+00:00

Hi @executekone , Appreciate the quick update here, I have taken a look at our data for the WP Staging plugin as well. I can confirm that the notification was a false positive as WP Staging (Free) 4.7.3 is not vulnerable to this issue. The short summary is that the alert fired as our system treated WP Staging Free like the Pro one for the version comparison. We’ve corrected this on our end already, so once your site re-syncs the new vulnerability data (~1 day), this warning should automatically disappear as a result. Thanks again for letting us know about this. Kind regards, Jarno

executekone 2026-04-17T16:13:00+00:00

Thank you very much.

executekone 2026-04-20T08:57:00+00:00

Hi @jarnovos , my site still shows WP Staging as vulnerable.

executekone 2026-04-20T18:17:00+00:00

It is now resolved. Thank you.

Jarno Vos 2026-04-21T13:15:00+00:00

Hi @executekone , Thanks a lot for confirming the solution, much appreciated. Kind regards, Jarno