redsand
Forum Replies Created
-
Forum: Everything else WordPress
In reply to: Version 4.74 Vulnerability?Hi @jsko40,
You are correct. 4.7.5 does not fix that issue. I was surprised to see that as well. However, all sites that have WP-SpamShield 1.9.9.9.9 or higher installed, will be protected.
– Scott
Hi @wfalaa,
Glad to help.
To clarify — the security issue being discussed in this thread is CVE-2017-8295. I need to correct one point you made: WP 4.7.5 does not fix this issue. It does fix several security issues, but not CVE-2017-8295. I audited the new WP code, and so have several other security experts. No edit whatsoever to the affected code. See its entry on WPScan Vulnerability DB for more info.
However, WP-SpamShield 1.9.9.9.9+ does mitigates the CVE-2017-8295 exploit, so all WP-SpamShield users are protected.
Let me know if I can help with anything else.
– Scott
Forum: Plugins
In reply to: [WP-SpamShield] security alertHi @iamediaworks,
I donโt use WPSS for security. I use it to prevent spam, period.
It’s important to remember that anti-spam and security are tightly intertwined, so even though you may not realize it, WP-SpamShield does quite a bit behind the scenes to improve site security. Granted, not many anti-spam plugins have the strong security focus that we do, but they’re also not as good at fighting spam. Security has always been a huge part of WP-SpamShield’s core values.
In 2017, it’s more important than ever for site owners to educate themselves on cybersecurity — at least the basics. We’re doing our part to help educate users on security. The vast majority of our users appreciate this.
The most recent version of WP still has the vulnerability, so that was not a mistake, and should not be ignored. We were surprised to see that they did not patch that issue. We just released an update, and since WP-SpamShield mitigates the security threat, users will not see the alert.
We appreciate the feedback and will consider that for the future.
And thanks for a great plugin!
You’re quite welcome! ๐
– Scott
Forum: Plugins
In reply to: [WP-SpamShield] security alertForum: Plugins
In reply to: [WP-SpamShield] security alertOk, please try to tone this down a bit. Flaming at us is not going to help anything. I would suggest that you target that frustration elsewhere.
then way are you splattering this huge red warnings across every websiteโฆ
Those are standard WordPress admin warnings. We added clarification since your initial support request, so users have more info, and know where the warnings come from, and where the data comes from.
and if you now say that your plugin protects the vulnerability then why are you still showing the warning????
The data comes from an external database. We had no idea that WordPress would release a security update, and yet not fix a known security issue. That’s the real issue.
If you noticed, we released our last update before the new WordPress was released. Unfortunately we can’t see into the future.
Instead of flaming at us, I would suggest simply communicating with your clients, that WordPress did not fix the issue, and that WP-SpamShield protects their sites. (Or if you have mitigated the issue by other means, then let them know that.)
We’ve done nothing but try to help you out. We’re not going to respond to any more of these types of messages on this thread.
If you have any further issues, you’ll need to direct them to the WP-SpamShield Tech Support Page.
– Scott
Forum: Plugins
In reply to: [WP-SpamShield] security alertYep. WordPress did not fix the vulnerability in the new security updates released today. Version 4.7.5 and all WordPress versions still have the vulnerability.
However, WP-SpamShield users are protected as of version 1.9.9.9.9.
Forum: Plugins
In reply to: [WP-SpamShield] Not compatible with q-translate-xHi @maginem,
On occasion we may provide updates here at the forum, but all our tech support is done through our site.
We don’t do tech support through the forums. In your case, we’ll need to run some tests and see what’s causing the issue. There are a lot of possibilities, and the info provided is simply too vague to be helpful. It could just be too, that qTranslate-X has not been updated in a year. (WP-SpamShield has been kept up to date.) We just won’t know until we run a few tests.
As noted in the forum sticky post linked above, please direct all support requests to the pluginโs official support venue, WP-SpamShield Technical Support.
– Scott
Forum: Everything else WordPress
In reply to: Version 4.74 Vulnerability?You’re welcome! ๐
Forum: Plugins
In reply to: [WP-SpamShield] What’s going on with Plugin Update???Outstanding. ๐ ๐
Forum: Everything else WordPress
In reply to: Version 4.74 Vulnerability?Hello everyone,
I just wanted to provide a quick update: WP-SpamShield version 1.9.9.9.9 has been released now, and provides mitigation for the CVE-2017-8295 WordPress zero-day exploit. Also, the security alerts have been improved to prevent confusion. Please see the changelog for more info.
– Scott
Forum: Plugins
In reply to: [WP-SpamShield] security alertHello everyone,
Just a quick update: WP-SpamShield version 1.9.9.9.9 has been released now, and provides mitigation for the CVE-2017-8295 WordPress zero-day exploit. Please see the changelog for more info.
– Scott
Forum: Fixing WordPress
In reply to: wpScan/wpvulndb Security Warning on fresh installJust a quick update: Version 1.9.9.9.9 has been released now, and provides mitigation for the CVE-2017-8295 WordPress zero-day exploit. Please see the changelog for more info.
You’re welcome! ๐ Version 1.9.9.9.9 has been released now, and provides mitigation for the WordPress zero-day exploit. Please see the changelog for more info.
Forum: Plugins
In reply to: [WP-SpamShield] What’s going on with Plugin Update???Hi Will,
That’s good to hear. Unless absolutely necessary, we won’t push out any more updates until this issue with the SVN is fixed. As long as the SVN is sync’ed, there shouldn’t be any issues, it’s only when new versions get added.
Right now though, I’m glad the update finally became available on WordPress.org, as it provides some important improvements, including mitigation for the CVE-2017-8295 WordPress zero-day exploit.
We’ll stay on top of things on our end as well.
– Scott
Forum: Plugins
In reply to: [WP-SpamShield] What’s going on with Plugin Update???The 1.9.9.9.9 update seems to be available now. Please try to update again. If anyone has further issues, let us know and we’ll provide a link on our site to download it manually.