False positive: version number range
-
Hi there!
I received a vulnerability notification that might point to a logic issue in your plugin.
I am using the Divi theme in version 4.27.7 and 5.8.1 on different sites. There is a CVE regarding versions 5.0 to 5.8.1: https://www.cve.org/CVERecord?id=CVE-2026-13712
I am getting a notification for both versions. However, version 4.27.7 is not affected and should not trigger the warning. I don’t know if this is an issue of the CVE data (is there a range, or is it just “less than 5.9.0”), or how your plugin evaluates the version number.
Could you have a look?
Kind regards,
Florian
The page I need help with: [log in to see the link]
You must be logged in to reply to this topic.