• Resolved caordawebsol

    (@caordawebsol)


    Will you be issuing a fix for this vulnerability?

    Constant Contact Forms plugin <= 1.14.0 – Broken Access Control vulnerability

Viewing 15 replies - 1 through 15 (of 33 total)
  • Plugin Author Constant Contact

    (@constantcontact)

    Can you provide where you’re seeing this report, or what tool you’re using to see this, so that we can get more information about reported issues and check on if our next release is going to already cover it or not?

    Any extra information would be greatly appreciated.

    Thread Starter caordawebsol

    (@caordawebsol)

    Plugin Author Constant Contact

    (@constantcontact)

    Thanks for the link, we’ll be reviewing it as soon as possible.

    PTaubman

    (@ptaubman)

    Checking in on this as well. Any ETA for an update that is not vulnerable?

    Or, do you have another preferred solution that replaces this?

    Thanks.

    Plugin Author Constant Contact

    (@constantcontact)

    We put the security related fix, pointed out with better detail for where from a review received this morning, in as part of the 2.0.0 major release that we pushed up to wordpress.org this afternoon.

    Thread Starter caordawebsol

    (@caordawebsol)

    Thank you!

    Thread Starter caordawebsol

    (@caordawebsol)

    When reconnecting using the code provided once logged into CC, the site throws a 500 error:


    An error of type E_ERROR was caused in line 754 of the file XXX/wp-content/plugins/constant-contact-forms/includes/class-lists.php. Error message: Uncaught Error: Cannot use object of type Ctct\Components\Contacts\ContactList as array in XXX/wp-content/plugins/constant-contact-forms/includes/class-lists.php:754

    Plugin Author Constant Contact

    (@constantcontact)

    Hi @caordawebsol we are checking on that right now. Thank you for the information

    Plugin Author Constant Contact

    (@constantcontact)

    You can download version 2.0.1 via https://downloads.wordpress.org/plugin/constant-contact-forms.2.0.1.zip and since you’re experiencing fatal errors, it’ll probably have to be a manual upload.

    Our apologies about that necessary step, it was definitely not our intention.

    Thread Starter caordawebsol

    (@caordawebsol)

    Thanks for addressing it so quickly – trying now.

    Thread Starter caordawebsol

    (@caordawebsol)

    Working great now – thanks so much!

    Thread Starter caordawebsol

    (@caordawebsol)

    Side note – show_title=false doesn’t seem to be working any more….

    [ctct form=”177″ show_title=”false”]

    Plugin Author Constant Contact

    (@constantcontact)

    @caordawebsol Not managing to recreate that issue with the title. Can you attempt saving the page where the shortcode is at and see if that somehow clears up the issue?

    Thread Starter caordawebsol

    (@caordawebsol)

    I’m now having issues syncing lists – once new code is copied over, it doesn’t “see” the lists. Screen shows zero lists, even after clicking sync

    Plugin Author Constant Contact

    (@constantcontact)

    Can you visit Settings > Support tab and enable the debugging setting? I’m curious if there’s already some logs in place in the debug log menu item that will show. If not, enable the debugging and re-try syncing the lists. Hopefully then something will show in the logs that we can use to troubleshoot.

Viewing 15 replies - 1 through 15 (of 33 total)

The topic ‘Security issue – will it be fixed??’ is closed to new replies.