WPIntell

Source evidence

WordFence reports cross site scripting vulnerability on v1.6.4

Meks Smart Social Widget · support · 2024-05-28T13:10:00+00:00

complaintsentiment
highseverity
0.97relevance
0replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 20 rows with source links

20.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

16 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
shu93129 unresolved
WordFence is reporting a cross site scripting vulnerability on version 1.6.4 of the plugin. This should probably be addressed else users may abandon the plugin. Vulnerability link: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/meks-smart-social-widget/meks-smart-social-widget-164-authenticated-admin-stored-cross-site-scripting — Full info from WordFence scan 25 May 2024 (version 1.6.4): The Plugin “Meks Smart Social Widget” has a security vulnerability. Type: Plugin Vulnerable Issue Found May 25, 2024 17:15. Critical Plugin Name: Meks Smart Social Widget Current Plugin Version: 1.6.4 Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Meks Smart Social Widget” until a patched version is available. Get more information ( https://www.wordfence.com/help/?query=scan-result-plugin-vulnerable ) Repository URL: https://wordpress.org/plugins/meks-smart-social-widget Vulnerability Information: https://www.wordfence.com/threat-intel/vulnerabilities/id/578ed437-98b7-495b-91fd-45b882f39d95?source=plugin Vulnerability Severity: 4.4/10.0 (Medium) The page I need help with: [ log in to see the link]

Comments

0 shown

No comments were stored for this source.