• Resolved majesticana

    (@majesticana)


    Hi support,

    I purchased the pro version of your plugin, installed it and it works fine. But I got this warnings from my hosting security:

    We have detected software vulnerabilities in PHP scripts on your web hosting package. To prevent system abuse resulting from exploitation of these vulnerabilities, these should be addressed as quickly as possible. This concerns the following vulnerabilities:
     
    Code injection vulnerability in WordPress (Unserialized objects can lead to remote code execution, allowing an attacker to take control of all the properties of the deserialized object)
    /wp-content/plugins/learning-management-system-pro/vendor/rmccue/requests/library/Requests/Session.php
     
    Code injection vulnerability in WordPress (Unserialized objects can lead to remote code execution, allowing an attacker to take control of all the properties of the deserialized object)
    /wp-content/plugins/learning-management-system-pro/vendor/rmccue/requests/library/Requests/Hooks.php
     
    Code injection vulnerability in WordPress (Unserialized objects can lead to remote code execution, allowing an attacker to take control of all the properties of the deserialized object)
    /wp-content/plugins/learning-management-system-pro/vendor/rmccue/requests/library/Requests/IRI.php
     
    Vulnerabilities such as these can allow third parties to access your web hosting package and abuse this through e.g. uploading malware for various purposes. We strongly recommend you check the entire web hosting package for other files that appear out of place, which our detection system might have missed.

    So, now I would like to ask you: Is your plugin safe for usage and what is the problem I am noticed in this warning about? It makes me VERY worried, so I’ve uninstalled your plugin for now. Thank you for explanation in advance.

    Kind regards

    • This topic was modified 4 months, 3 weeks ago by Jan Dembowski.
    • This topic was modified 4 months, 3 weeks ago by Jan Dembowski.
    • This topic was modified 4 months, 3 weeks ago by majesticana.
Viewing 3 replies - 1 through 3 (of 3 total)
  • Moderator Support Moderator

    (@moderator)

    I purchased the pro version of your plugin

    The developer cannot and must not support customers on this site. They risk getting into real trouble if they do.

    For pro or customer support, please contact the developer on their site. This includes pre-sales information.

    As the developer is aware, customers may not be supported on this site.

    https://wordpress.org/support/guidelines/#do-not-post-about-commercial-products

    Thread Starter majesticana

    (@majesticana)

    @moderator OK, I will contact their support using their official website.
    Thank you for your respond and sorry for my mistake.

    Kind regards

    Plugin Support Amrit Kumar Shrestha

    (@shresthauzwal)

    Hi @majesticana,

    If you are using the premium version, please reach out to our support team through live chat or the contact form since this forum is for the free version of the plugin.

    As you have posted your topic here regarding the plugin safety, we want to let you know that the security issue has been fixed, and a patch has been released.

    This topic is not related to the free plugin, so we are closing it.

    Best regards!

Viewing 3 replies - 1 through 3 (of 3 total)
  • You must be logged in to reply to this topic.