• Resolved WP3DW

    (@wp3dw)


    i see that the plugin has now been removed from the WordPress plugin repository. So this plugin is not getting a fix for the security issue mentioned? Or is this plugin under review?

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Author Daniel Iser

    (@danieliser)

    Hi @wp3dw — the fix has been released as version 2.6.6 and submitted to WordPress.org. The plugin is currently awaiting their review.

    The report concerned a read-only endpoint intentionally used for public-facing settings, such as CSS breakpoints and the default denial message. It did not expose restrictions or private administrative data, as reported.

    Version 2.6.6 now requires authorization for that endpoint.

    Per wordpress.org:

    Version 2.6.6 will be released to sites in about 5 hours. WordPress.org currently delays plugin updates by 6 hours so moderators and security scanners can review changes before they reach users. 
    • This reply was modified 1 day, 18 hours ago by Daniel Iser.

    @danieliser thanks for looking into this, however the plugin continues to be removed from the WordPress repository. Any update?

    Plugin Author Daniel Iser

    (@danieliser)

    @realact – In this case it requires WordPress plugins team to approve the patch. Patch was in early Friday but it simply may not get reviewed til Monday or so if I had to guess they aren’t working weekends like many others.

Viewing 3 replies - 1 through 3 (of 3 total)

You must be logged in to reply to this topic.