Forum Replies Created

Viewing 15 replies - 106 through 120 (of 1,410 total)
  • Hi @jsko40,

    You are correct. 4.7.5 does not fix that issue. I was surprised to see that as well. However, all sites that have WP-SpamShield 1.9.9.9.9 or higher installed, will be protected.

    – Scott

    Hi @wfalaa,

    Glad to help.

    To clarify — the security issue being discussed in this thread is CVE-2017-8295. I need to correct one point you made: WP 4.7.5 does not fix this issue. It does fix several security issues, but not CVE-2017-8295. I audited the new WP code, and so have several other security experts. No edit whatsoever to the affected code. See its entry on WPScan Vulnerability DB for more info.

    However, WP-SpamShield 1.9.9.9.9+ does mitigates the CVE-2017-8295 exploit, so all WP-SpamShield users are protected.

    Let me know if I can help with anything else.

    – Scott

    Plugin Contributor redsand

    (@redsand)

    Hi @iamediaworks,

    I donโ€™t use WPSS for security. I use it to prevent spam, period.

    It’s important to remember that anti-spam and security are tightly intertwined, so even though you may not realize it, WP-SpamShield does quite a bit behind the scenes to improve site security. Granted, not many anti-spam plugins have the strong security focus that we do, but they’re also not as good at fighting spam. Security has always been a huge part of WP-SpamShield’s core values.

    In 2017, it’s more important than ever for site owners to educate themselves on cybersecurity — at least the basics. We’re doing our part to help educate users on security. The vast majority of our users appreciate this.

    The most recent version of WP still has the vulnerability, so that was not a mistake, and should not be ignored. We were surprised to see that they did not patch that issue. We just released an update, and since WP-SpamShield mitigates the security threat, users will not see the alert.

    We appreciate the feedback and will consider that for the future.

    And thanks for a great plugin!

    You’re quite welcome! ๐Ÿ™‚

    – Scott

    Plugin Contributor redsand

    (@redsand)

    @mikes-1

    I’m sorry to hear you feel that way, but you’re always free to do as you like.

    @abigailm

    Thanks for your feedback, we always take that into consideration.

    Plugin Contributor redsand

    (@redsand)

    @mikes-1,

    Ok, please try to tone this down a bit. Flaming at us is not going to help anything. I would suggest that you target that frustration elsewhere.

    then way are you splattering this huge red warnings across every websiteโ€ฆ

    Those are standard WordPress admin warnings. We added clarification since your initial support request, so users have more info, and know where the warnings come from, and where the data comes from.

    and if you now say that your plugin protects the vulnerability then why are you still showing the warning????

    The data comes from an external database. We had no idea that WordPress would release a security update, and yet not fix a known security issue. That’s the real issue.

    If you noticed, we released our last update before the new WordPress was released. Unfortunately we can’t see into the future.

    Instead of flaming at us, I would suggest simply communicating with your clients, that WordPress did not fix the issue, and that WP-SpamShield protects their sites. (Or if you have mitigated the issue by other means, then let them know that.)

    We’ve done nothing but try to help you out. We’re not going to respond to any more of these types of messages on this thread.

    If you have any further issues, you’ll need to direct them to the WP-SpamShield Tech Support Page.

    – Scott

    Plugin Contributor redsand

    (@redsand)

    Yep. WordPress did not fix the vulnerability in the new security updates released today. Version 4.7.5 and all WordPress versions still have the vulnerability.

    However, WP-SpamShield users are protected as of version 1.9.9.9.9.

    Plugin Contributor redsand

    (@redsand)

    Hi @maginem,

    On occasion we may provide updates here at the forum, but all our tech support is done through our site.

    We don’t do tech support through the forums. In your case, we’ll need to run some tests and see what’s causing the issue. There are a lot of possibilities, and the info provided is simply too vague to be helpful. It could just be too, that qTranslate-X has not been updated in a year. (WP-SpamShield has been kept up to date.) We just won’t know until we run a few tests.

    As noted in the forum sticky post linked above, please direct all support requests to the pluginโ€™s official support venue, WP-SpamShield Technical Support.

    – Scott

    @diver8642

    You’re welcome! ๐Ÿ™‚

    Plugin Contributor redsand

    (@redsand)

    Outstanding. ๐Ÿ‘ ๐Ÿ™‚

    Hello everyone,

    I just wanted to provide a quick update: WP-SpamShield version 1.9.9.9.9 has been released now, and provides mitigation for the CVE-2017-8295 WordPress zero-day exploit. Also, the security alerts have been improved to prevent confusion. Please see the changelog for more info.

    – Scott

    Plugin Contributor redsand

    (@redsand)

    Hello everyone,

    Just a quick update: WP-SpamShield version 1.9.9.9.9 has been released now, and provides mitigation for the CVE-2017-8295 WordPress zero-day exploit. Please see the changelog for more info.

    – Scott

    Just a quick update: Version 1.9.9.9.9 has been released now, and provides mitigation for the CVE-2017-8295 WordPress zero-day exploit. Please see the changelog for more info.

    You’re welcome! ๐Ÿ™‚ Version 1.9.9.9.9 has been released now, and provides mitigation for the WordPress zero-day exploit. Please see the changelog for more info.

    Plugin Contributor redsand

    (@redsand)

    Hi Will,

    That’s good to hear. Unless absolutely necessary, we won’t push out any more updates until this issue with the SVN is fixed. As long as the SVN is sync’ed, there shouldn’t be any issues, it’s only when new versions get added.

    Right now though, I’m glad the update finally became available on WordPress.org, as it provides some important improvements, including mitigation for the CVE-2017-8295 WordPress zero-day exploit.

    We’ll stay on top of things on our end as well.

    – Scott

    Plugin Contributor redsand

    (@redsand)

    The 1.9.9.9.9 update seems to be available now. Please try to update again. If anyone has further issues, let us know and we’ll provide a link on our site to download it manually.

Viewing 15 replies - 106 through 120 (of 1,410 total)