Hi @zantafio
Thanks for reaching out.
Yes, v3.3.72 is secure and you can update the plugin.
No it’s not secure: https://patchstack.com/database/wordpress/plugin/download-manager/vulnerability/wordpress-download-manager-plugin-3-3-71-sensitive-data-exposure-vulnerability. The warning is: WordPress Download Manager Plugin <= 3.3.72 is vulnerable to Sensitive Data Exposure
-
This reply was modified 2 days, 21 hours ago by
NHWS.
-
This reply was modified 2 days, 21 hours ago by
NHWS.
@nhws, it was precisely because of that warning on Patchstack that I asked. I recently had a similar issue with another plugin; according to the plugin provider, the latest version was safe, but the information on Patchstack hadn’t been updated yet. I hope that’s the case here too…
Yes, that might be the case for patchstack @zantafio
There is no vulnerability in v3.3.72. You can also check here:
https://wpscan.com/plugin/download-manager/
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/download-manager
-
This reply was modified 2 days, 11 hours ago by
Tahasin.
-
This reply was modified 2 days, 10 hours ago by
Tahasin.
@tahasin, please request an update at PatchStack then. This is also in your benefit as PatchStack is leading and a lot of users will have the same problem.
Hi @nhws
We are investigating the issue and will provide an update here as soon as we have more information.
Appreciate your patience.
@tahasin, thank you very much for your quick reply, and good luck!
Thanks @tahasin, Patchstack just mailed me the following:
Hey, it was marked as patched, we had issues with vendor communication, at first they missed our report due to issues with they web contact form, then they noticed disclosed vulnerability, asked us to provide details and again their form failed, so we were a bit disconnected from them.
Darius
Patchstack
Thanks for sharing Patchstack’s response @nhws .
Everything is okay now, and you can safely update the plugin to the latest version, 3.3.72.
yes, all good now. Thanks!