Viewing 5 replies - 1 through 5 (of 5 total)
  • Any update on when this will be fixed?

    Plugin Author Marcus

    (@msykes)

    Hello,

    Thanks for reporting this, although ideally security reports should be kept out of public spaces. Since it’s out there:

    I THINK this has been patched already. We’ve patched some 40 vulnerabilities over the past month. A few of those were early this week. Many originated via WordFence. Some vulnerabilities from other plugins we manage were derived from Patchstack reports, so I’m wondering if maybe that’s the case here too. Unfortunately I haven’t seen this report from Patchstack so I’m waiting on them to give me access to the comprehensive report. However, given they’ve announced it already makes me think there’s a duplicate report floating about.

    That said… we’ve scanned the plugin again and have in fact found a related XSS vulnerability, which we’re patching now.

    Given the report is publicly disclosed, I’m assuming they came across it earlier on than this week, so there’s a high chance it’s the same one reported to WordFence and we have a cross-post.

    Plugin Author Marcus

    (@msykes)

    I replied earlier, but my comment is in moderation. In a nutshell; we’re putting out an update now which fixes another issue, but the one reported may well have been fixed already, given we updated the plugin this week. The versioning on their side is likely automatic until confirmed patched.

    Thread Starter terry789

    (@terry789)

    Hello Marcus,

    although ideally security reports should be kept out of public spaces

    You are right, sorry for my mistake.

    Thanks

    Very irritatingly, Patchstack is now showing 7.4.2 as being vulnerable as well, however the CVE record (2026-66457) still only list <=7.4.1

    I think I’ve seen this sort of version confusion with Patchstack before, so I’m never completely convinced when this sort of confusion happens.

Viewing 5 replies - 1 through 5 (of 5 total)

You must be logged in to reply to this topic.