• Resolved willnev

    (@willnev)


    Hi – I received a warning that there is a security issue with this plugin. Any idea on when a fix will be deployed?

Viewing 11 replies - 1 through 11 (of 11 total)
  • Plugin Author Denis Botić

    (@strongetic)

    Hi,
    thank you for bringing this to my attention.
    I will look into this issue immediately and work on a fix as soon as possible.
    I’ll keep you updated here.

    Denis Botic

    Thread Starter willnev

    (@willnev)

    Thank you for your quick response! I appreciate you looking into it.

    Plugin Author Denis Botić

    (@strongetic)

    I am currently working on a fix and reviewing the code.

    To help me pinpoint the exact issue, could you share the precise security message or log you received?

    I ask because there are three specific things in the code that automated scanners sometimes falsely flag as issues, and I have already included security description comments explaining why they are safe.

    Aside from those, I found two other low-risk areas and have already bulletproofed them.

    Having the exact message will help me confirm if the report is referring to a false positive or something else entirely.

    Thank you for your help!

    Thread Starter willnev

    (@willnev)

    Understood and thank you for working so quickly on this! Below is a link to the PatchStack post regarding the issue.

    https://patchstack.com/database/wordpress/plugin/page-visits-counter-lite/vulnerability/wordpress-page-visits-counter-lite-plugin-1-2-3-cross-site-scripting-xss-vulnerability

    Plugin Author Denis Botić

    (@strongetic)

    Thank you for providing the link! This gives me exactly what I need.

    You can completely relax and continue using the plugin safely. This report is essentially a technical false positive caused by how automated security scanners work. They flag code if it doesn’t strictly use specific WordPress escaping functions before outputting data, even if the data itself is already completely secure.

    Here is why your site is 100% safe from this right now:

    • No Frontend User Input: The plugin does not send or accept any data from regular frontend visitors after the page loads.
    • Protected Data Sources: The data displayed by the plugin consists of standard WordPress post titles, page names, or WooCommerce products. Only logged-in users with high-level administrative privileges can create these titles in the first place, and WordPress natively sanitizes them.
    • Strict Integer Formatting: The only data an administrator can input directly related to the plugin are visit numbers, which are strictly forced to be integers (numbers) before being saved to the database. There is simply no entry point for malicious scripts.

    What’s next?
    Even though there is no real-world security vulnerability here, I want to keep the automated scanners happy so you don’t have to see these warnings. I am wrapping up a security update over the weekend and plan to publish the new version by Monday. This update will implement explicit escaping functions to clear this notice from Patchstack entirely.

    Thank you again for your patience and for helping keep the plugin safe!

    Thread Starter willnev

    (@willnev)

    That’s great! Thank you so much for the reassurance and the updates you’ll be pushing out. It’s great;y appreciated!

    Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    @willnev I’ve removed your post because it details an exploit. Not something that should be widely distributed. @strongetic , please give them a private way of contacting you if you’re interested in this info.

    Plugin Author Denis Botić

    (@strongetic)

    Hi everyone,

    Thank you for reporting this issue and for your patience.

    I sincerely apologize for the inconvenience. Due to a deployment glitch during last night’s update, a few crucial files (including class-export-csv.php) failed to transfer from my local environment to the WordPress repository. This is what caused the Fatal Error on your websites.

    I am already actively working on a fix. You might see a few minor version updates rolling out shortly as I test the deployment. Please do not update or download the plugin until I post a confirmation here that it is completely safe to do so.

    I will update this thread the exact moment the stable fix is live. Thank you for your understanding!

    Thread Starter willnev

    (@willnev)

    Thank you!

    Thread Starter willnev

    (@willnev)

    @strongetic – Thank you! Totally understand! Thank you!

    Plugin Author Denis Botić

    (@strongetic)

    UPDATE: The stable fix is now live (Version 2.0.5)!

    I am happy to confirm that Version 2.0.5 is fully safe, stable, and includes the necessary security update. If your website was affected by the fatal error, updating to this version will resolve the issue and bring your site back online.

    I want to thank all of you so much for your incredible patience and understanding. I also wanted to explain why this fix took a bit longer to appear: after pushing the corrected code to the official WordPress repository, we had to wait about 6 hours for WordPress to complete all its automated security scans and reviews. Only after those checks were successful did WordPress make the update available in your WP admin dashboards.

    What you need to do now:

    • If your site has automatic updates enabled: It should automatically pull Version 2.0.5 and fix itself within the next few hours (once your site’s WordPress cron job runs).
    • If you can access your WP Admin dashboard: Please go to Plugins > Installed Plugins and manually click Update on this plugin.
    • If your website is still showing a blank screen (Fatal Error) and you cannot access the dashboard:
      1. Log into your server via FTP or cPanel File Manager.
      2. Navigate to wp-content/plugins/ and delete or rename the folder of this plugin (this will bring your site back instantly).
      3. Log back into your WP Admin, download Version 2.0.5 from the plugin repository, and activate it.

    Thank you again for standing by me while I resolved this. Please let me know if everything is back to normal on your end!

    Best regards,
    Denis Botić

Viewing 11 replies - 1 through 11 (of 11 total)

You must be logged in to reply to this topic.