jreedpasd
Forum Replies Created
-
I also forgot to add that are main theme for the web site is Divi
Thanks for getting back and sorry for the delay. This issue currently impacting several sites more than just the one we saw in the beginning.
To answer some of your questions:
WordPress version: 6.7.2
PHP Version: 8.2
Plugins that I believe are creating post types are Formidable and NextGen Gallery. We also have “tickets” enabled within the Events Calendar.
The issue still remains when I enable the Twenty Twenty One theme with the Events Calendar only.Not necessarily an issue but we have a contact form that includes first name, last name, etc. Our security consultants tested the form and used html code like
<a href="http://www.google.com">Jason</a>within the first name text field.When we received the notification from the contact form, the html code came through as a hyperlink. Our security team sees this as a vulnerability with the plugin since its not cleansing the html code. They see this as someone could submit a link hoping someone would click on it and send them to a malicious website.
- This reply was modified 2 years, 11 months ago by Steven Stern (sterndata). Reason: code format