On a site that I manage where Kirki is installed with 6.0.14 no alert from Wordfence or Sucuri, the vulnerability from the previous version seems fixed.
Hello @mealsbymavis @overylewdeneliva,
We take security very seriously and prioritize applying updates as soon as possible. Please note that security vendor databases sometimes take a bit of time to update their records, even after a patch has been deployed or the risk has been assessed.
Our team is actively looking into this specific notice to ensure that your website remains secure.
@newmediologo, Thank you for your feedback.
Best regards,
Nafiz | Kirki Support Team
JLY
(@jose-luis-yanez)
Hello, I confirm that I am still seeing the warning from patchstack,
even after having updated to versión 6.0.14, here:
https://patchstack.com/database/wordpress/plugin/kirki/vulnerability/wordpress-kirki-plugin-6-0-13-broken-access-control-vulnerability
The warning: “WordPress Kirki Plugin <= 6.0.14 is vulnerable to a high priority Broken Access Control”
Please update,
Thank you,
After the latest update, the website based on the Cosmetsy theme stopped working. It now displays only a blank white screen. I also dont have access to admin panel
-
This reply was modified 3 days, 14 hours ago by
kmnoworyta.