• Resolved jpfssi

    (@jpfssi)


    I have a custom theme that I manage for my site that has a similar name to a completely different theme that has been flagged as high-risk by the RSS plugin (https://vulnerabilities.really-simple-security.com/theme/splash/a40fbf9c-d197-4337-bb6c-dfbdc1b4b0f1/).

    My Splash theme is not based on any other theme and is something built only for our site. How can I remove the High-Risk Vulnerability notification from the RSS plugin? I do not see a dismiss or resolved button in the plugin for this issue. It has also been over a week since this notification was seen and it has not been removed.

    The page I need help with: [log in to see the link]

Viewing 4 replies - 1 through 4 (of 4 total)
  • Plugin Support Jarno Vos

    (@jarnovos)

    Hi @jpfssi,

    I see. The vulnerability scanner identifies themes by folder slug (splash) and then queries our vulnerability API with the slug + theme name + type.

    The public Splash theme vulnerability affects versions <= 4.4.3 and was fixed in 4.4.4. So, your custom theme with the same slug (splash) and a version below 4.4.4 will indeed be flagged, even if it is a completely different theme that’s not affected by that issue; since the plugin has no reliable way to distinguish these from eachother.

    For now, the easiest fix would be to set your splash theme to use a higher version number than 4.4.3, by setting it to Version: 4.4.4 or higher in your custom theme’s style.css file. After doing so, it will take ~1 day for the plugin to re-sync the new data, and the notice will disappear afterwards.

    In a future release, we will add a clearer method to dismiss or exclude individual plugins and themes from the vulnerability scanner to avoid receiving unwanted notices for components like these.

    Hope this helps. Kind regards, Jarno

    Thread Starter jpfssi

    (@jpfssi)

    Thank you for the solution. I’ll go ahead and test this out and see if it fixes the issue.

    Thread Starter jpfssi

    (@jpfssi)

    This workaround seems to have worked. Thanks

    Plugin Support Jarno Vos

    (@jarnovos)

    Glad to hear, appreciate the confirmation @jpfssi!

    Kind regards, Jarno

Viewing 4 replies - 1 through 4 (of 4 total)

You must be logged in to reply to this topic.