• Resolved forthangel

    (@forthangel)


    Hi. Awesome plugin. I have a question though. When using the plugin to create a popup and running a Google audit from Chrome on the page with the popup, I get a warning about Jquery UI 1.11.4. It says I’m using a front-end library that is vulnerable.

    Is this something the plugin itself is packaged with and using, or is the Jquery UI version something I need to update myself and the plugin only uses it to function? Disabling the plugin removes the warning.

    Jquery UI 1.11.4 seems to have a really high risk of XSS injection, so I’d like to know if I should remove the plugin to get rid of this vulnerability or if I should research how to update Jquery UI.

    If it helps, I’m already using Jquery Updater.

    The page I need help with: [log in to see the link]

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author Popup Maker

    (@popupmaker)

    Hello @forthangel,
    We don’t use Jquery UI inside our popup’s. I guess this issue is not connected to us but another plugin or your current theme.
    To make sure the issue is not related to us you can temporarily disable popup or plugin and run the tests again.

    Please let us know about your progress.

    Thanks.

    Thread Starter forthangel

    (@forthangel)

    I only get the warning when the popup maker plugin is active. Once I disable the plugin, the warning doesn’t show up in the audit.

    Current WordPress and Theme versions:

    WordPress v. 4.9.8
    Theme, U-Design v. 2.13.17

    I have 1 popup created:

    Time delay: 500ms
    Cookies: no
    Target: single page
    Theme: Uncustomized EnterpriseBlue
    Close Button: Active with a 500ms delay.

    But if your plugin doesn’t use Jquery UI then I have no idea where else to start. I only get the warning when it is active. I used to get this same warning when using Accordions if that is any help.

    Could the Google audit be bugging out and giving false information?

    Plugin Author Popup Maker

    (@popupmaker)

    Hey @forthangel
    Could you please make sure if you are using our service https://popupmaker.com ?
    Is there any way we can see the site live with the popup inside?

    Thread Starter forthangel

    (@forthangel)

    -_-

    It wasn’t yours. I had two installed I was going to try and clicked the wrong one for support. I actually dunno if yours gives the warning but it probably doesn’t if you don’t use jquery ui.

    Also, didn’t realize yours needed an API key, but I may give it a shot if it doesn’t include vulnerabilities like the other one.

    Sorry for the bother..

    Plugin Author Popup Maker

    (@popupmaker)

    We will be happy if you can give it a try. We are constantly monitoring the system and there should not be any vulnerabilities.

    Feel free to contact us in case of any other question.

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Jquery UI 1.11.4’ is closed to new replies.