• Resolved aapc

    (@aapc)


    Patchstack has published a Cross Site Scripting (XSS) issue for <= 1.36.3. Albeit a low priority issue, it would be great if this was addressed soon. Thanks!

    The page I need help with: [log in to see the link]

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Author Andrew Wilder

    (@eatingrules)

    Hi @aapc — thanks for bringing this to our attention!

    This is the first we’re hearing of this (even though we had joined Patchstack’s mVDP program! 🤦‍♂️).

    We will look into it and get it addressed as soon as possible.

    Thanks,
    Andrew

    Plugin Author Andrew Wilder

    (@eatingrules)

    We’ve released version 1.36.3.1 which addresses the vulnerability (confirmed by Patchstack).

    Just waiting for the 6-hour delay so that it becomes available; we’ve also emailed the plugins team to see if they can drop that waiting period. So we’re all set. 😊

    Thread Starter aapc

    (@aapc)

    Thanks for the quick response and update!

Viewing 3 replies - 1 through 3 (of 3 total)

You must be logged in to reply to this topic.