Support » Plugin: The Events Calendar » Firebase/JWT Library version outdated

  • Hi,

    I’m a plugin developer and one of my plugins uses the Firebase\JWT library too, my users and I find out that when my plugin and yours are installed in the same WP installation my plugin stop working as expected.

    Digging in I found out that you are using an outdated Firebase/JWT version my plugin uses version 6.3 and there are breaking changes between both versions 5.0.0 and 6.3.

    Also, versions below 6.0 have a security vulnerability, you can ping me (@tmeister) privately to send you the link if you are not aware of that.

    Thanks in advance

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Author Gustavo Bordoni

    (@bordoni)

    Hi @tmeister,

    We will handle the update. Please do not disclose security problems in an open forum without reaching out to the developers privately first. It exposes customers that might be using both plugins unnecessarily.

    We only use the encoding part of the JWT Firebase, so when only using The Events Calendar, there is no way to exploit the problem.

    I’ve marked this for the Mods to remove, I hope you understand. We are already handling the problem reported.

    Best regards,

    Plugin Support Abz

    (@abzlevelup)

    Hi @tmeister, apologies for the delay here. We already released a fix regarding JWT Firebase issue with The Events Calendar. Could you try upgrading to v6.0.2+ and see if that fixes the issue here?

    Please let us know how it goes.

    Best,
    Abz

Viewing 2 replies - 1 through 2 (of 2 total)
  • You must be logged in to reply to this topic.