Conversation
supportjust got a notice from wordfence that plugin is vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection Freemius SDK <= 2.4.2 – Missing Authorization Checks https://www.wordfence.com/threat-intel/vulnerabilities/detail/freemius-sdk-242-missing-authorization-checks https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-tracker
The Email Tracker 5.3.14 (Latest release) version uses the Freemius SDK 2.12.1 version, the latest Email Tracker 5.3.14 version has no vulnerability. Update the Email Tracker plugin.
its already updated but why wordfence still picks it up as vulnerable?
@koullis Thanks for reporting it. Let me connect with Wordfence team. Once I will get update, I will update you here.
ok thanks will wait for your update
The Wordfence team has just marked the Email Tracker plugin as patched, so the Email Tracker plugin issue has been resolved.
The Email Tracker 5.3.14 (Latest release) version uses the Freemius SDK 2.12.1 version, the latest Email Tracker 5.3.14 version has no vulnerability. Update the Email Tracker plugin.
its already updated but why wordfence still picks it up as vulnerable?
@koullis Thanks for reporting it. Let me connect with Wordfence team. Once I will get update, I will update you here.
ok thanks will wait for your update
The Wordfence team has just marked the Email Tracker plugin as patched, so the Email Tracker plugin issue has been resolved.