• Hello,

    Wordfence has flagged version <= 7.4.2 as vulnerable and recommended deleting the plugin. Is there a patched version out soon?

    Thanks.

Viewing 2 replies - 1 through 2 (of 2 total)
  • @msykes must be incredibly frustrating after the flurry of timely security updates you’ve prepared. Have you attempted to reach out to patchstack, wordfence or the researcher https://patchstack.com/database/researchers/f42f9005-6b3c-4dec-9a30-3dd729b55bc3 for clarity?

    If there is anything we at the community can do? I am cross posting this same comment to the below thread as well.

    I see in the changelog for 7.4.2 the following:

    Security: Fixed an XSS vulnerability in grouped event lists (possibly CVE-2026-66457).

    So, it’s likely this is already fixed. Patchstack will continue to report it as not fixed until the reporter verifies that 7.4.2 fixes the vulnerability. and WordPress will also report it if Patchstack still indicates it’s not yet fixed in 7.4.2.

    The vulnerability only occurs for grouped event lists so if you’re not using “groupby” when outputting your event lists then this vulnerability would not impact your website.

Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.