WPIntell

Source evidence

Vulnerability Reported on iThemes

Scripts n Styles · support · 2023-05-19T15:05:00+00:00

mixedsentiment
highseverity
0.95relevance
6replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 31 rows with source links

16.1% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
cowanservices resolved
We use Scripts n Styles on almost all of our sites. iThemes is reporting a Cross Site Scripting vulnerability w/no fix available. Also there hasn’t been an update in 10 months. Do we bail and use something else? Or will there be a fix. We have close to 100 sites. Thanks! Lisa The page I need help with: [ log in to see the link] Hello, I don’t work on this plugin that often anymore, but if there’s details on how I can patch the issue, I will certainly do so. I’ll need more details however, since there’s nothing here to go on. Is there a specific note about what exactly the vulnerability is supposed to be? @wraithkenny : I also got a critical warning, Here is some more information from wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/scripts-n-styles/scripts-n-styles-352-authenticated-administrator-stored-cross-site-scripting “This only impacts multi-site installations and installations where unfiltered_html has been disabled.” As noted on the other thread, this is certainly a false positive, since the admin code is completely disabled when unfiltered_html is disabled. Thanks for linking to that, much appreciated. I’ve release 3.5.3, which disables the plugin completely if DISALLOW_UNFILTERED_HTML is set to true, and also disables the old code for upgrading meta data with the old key. This should remove any surface for the reported vulnerability. Great, thanks! Just for your info, the original reporters have marked this as fixed on their site, you shouldn’t see any warnings anymore.

Comments

6 shown
WraithKenny 2023-05-25T15:02:00+00:00

Hello, I don’t work on this plugin that often anymore, but if there’s details on how I can patch the issue, I will certainly do so. I’ll need more details however, since there’s nothing here to go on. Is there a specific note about what exactly the vulnerability is supposed to be?

sara.mansouri 2023-05-25T21:42:00+00:00

@wraithkenny : I also got a critical warning, Here is some more information from wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/scripts-n-styles/scripts-n-styles-352-authenticated-administrator-stored-cross-site-scripting

WraithKenny 2023-05-26T02:05:00+00:00

“This only impacts multi-site installations and installations where unfiltered_html has been disabled.” As noted on the other thread, this is certainly a false positive, since the admin code is completely disabled when unfiltered_html is disabled. Thanks for linking to that, much appreciated.

WraithKenny 2023-05-26T15:13:00+00:00

I’ve release 3.5.3, which disables the plugin completely if DISALLOW_UNFILTERED_HTML is set to true, and also disables the old code for upgrading meta data with the old key. This should remove any surface for the reported vulnerability.

sara.mansouri 2023-06-01T22:44:00+00:00

Great, thanks!

WraithKenny 2023-06-08T18:44:00+00:00

Just for your info, the original reporters have marked this as fixed on their site, you shouldn’t see any warnings anymore.