Title: stopps's Replies | WordPress.org

---

# stopps

  [  ](https://wordpress.org/support/users/stopps/)

 *   [Profile](https://wordpress.org/support/users/stopps/)
 *   [Topics Started](https://wordpress.org/support/users/stopps/topics/)
 *   [Replies Created](https://wordpress.org/support/users/stopps/replies/)
 *   [Reviews Written](https://wordpress.org/support/users/stopps/reviews/)
 *   [Topics Replied To](https://wordpress.org/support/users/stopps/replied-to/)
 *   [Engagements](https://wordpress.org/support/users/stopps/engagements/)
 *   [Favorites](https://wordpress.org/support/users/stopps/favorites/)

 Search replies:

## Forum Replies Created

Viewing 11 replies - 1 through 11 (of 11 total)

 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[WP-Polls] PatchStack Reporting Cross Site Scripting (XSS)](https://wordpress.org/support/topic/patchstack-reporting-cross-site-scripting-xss/)
 *  Thread Starter [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/patchstack-reporting-cross-site-scripting-xss/#post-18979846)
 * Hi Lester,
 * Thanks for the response, I’ll schedule some time to take a look at the new AI
   version and do some testing.
 * Just so you are aware, Wordfence are now also reporting the new issue: [https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-polls/wp-polls-2773-authenticated-administrator-stored-cross-site-scripting](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-polls/wp-polls-2773-authenticated-administrator-stored-cross-site-scripting)
 * They are classifying it as low risk as it is an Administrator+ exploit:
 * “The WP-Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting
   in versions up to, and including, 2.77.3 due to insufficient input sanitization
   and output escaping. This makes it possible for authenticated attackers, with
   administrator-level access and above, to inject arbitrary web scripts in pages
   that will execute whenever a user accesses an injected page. This only affects
   multi-site installations and installations where unfiltered_html has been disabled.”
 * I’m not sure how this can be classified as a vulnerability if someone has chosen
   to disabled unfiltered_html, but you’ll probably want to issue a patch just to
   avoid the plugin directory restricting the plugin’s access.
 * All the best,
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[LazyLoad Plugin – Lazy Load Images, Videos, and Iframes] Please remove Polyfill supply chain attack](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/)
 *  [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [2 years ago](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/#post-17885273)
 * [@coquardcyr](https://wordpress.org/support/users/coquardcyr/) Excellent – many
   thanks, looking forward to getting this reactivated on client sites. Good work.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[LazyLoad Plugin – Lazy Load Images, Videos, and Iframes] Please remove Polyfill supply chain attack](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/)
 *  [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [2 years ago](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/#post-17883558)
 * [@coquardcyr](https://wordpress.org/support/users/coquardcyr/) Thanks for confirming
   the removal in version 2.3.8, do you have a timeline for when this will be released?
 * All the best,
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[LazyLoad Plugin – Lazy Load Images, Videos, and Iframes] Please remove Polyfill supply chain attack](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/)
 *  [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [2 years, 1 month ago](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/#post-17868542)
 * [@coquardcyr](https://wordpress.org/support/users/coquardcyr/) – Thanks for getting
   back to to me. The reference has been removed from:
 * /rocket-lazy-load/vendor/wp-media/rocket-lazyload-common/src/Assets.php
 * from but not from:
 * vendor/wp-media/rocket-lazyload-common/src/Assets.php
 * Which means the plugin is still being flagged by security software. I’m looking
   at Version 2.3.7.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[LazyLoad Plugin – Lazy Load Images, Videos, and Iframes] Please remove Polyfill supply chain attack](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/)
 *  [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [2 years, 1 month ago](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/#post-17865577)
 * As sel has mentioned, this plugin still contains a reference to pollyfill.io 
   in the file:
 * /vendor/wp-media/rocket-lazyload-common/src/Assets.php
 * Can this be addressed so we can reactivate it as a safe plugin?
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[LazyLoad Plugin – Lazy Load Images, Videos, and Iframes] Please remove Polyfill supply chain attack](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/)
 *  [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [2 years, 1 month ago](https://wordpress.org/support/topic/please-remove-polyfill-supply-chain-attack/#post-17853363)
 * Seconding this request – the file:
 * /src/Dependencies/RocketLazyload
   /Assets.php
 * has a reference to pollyfill.io, loading a JavaScript file from this domain (
   which as Sebastian has pointed out is now considered compromised). Please move
   this to either CloudFlare’s mirror or bring the file local (from a trusted source).
 * We recommend anyone using this plugin deactivated it until an update has been
   issued to correct this issue.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[SVG Support] Updating Failed when try to update a page](https://wordpress.org/support/topic/updating-failed-when-try-to-update-a-page/)
 *  [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [2 years, 1 month ago](https://wordpress.org/support/topic/updating-failed-when-try-to-update-a-page/#post-17813574)
 * We’ve also started experiencing this issue, ACF versions 6.3.1 through to 6.3.1.2,
   SVG Support 2.5 through to 2.5.5. Oddly we don’t see it on every site instance.
   Disabling SVG Support resolves the issue.
 * Should we expect the SVG Support plugin to be updated? We are moving to Safe 
   SVG as a temporary solution for impacted sites.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Comments Like Dislike] Wordfence and PatchStack Flagging Security Issue](https://wordpress.org/support/topic/wordfence-and-patchstack-flagging-security-issue/)
 *  Thread Starter [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [2 years, 5 months ago](https://wordpress.org/support/topic/wordfence-and-patchstack-flagging-security-issue/#post-17446760)
 * Thanks for actioning so promptly, much apprecaited.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Comments Like Dislike] Security Vulnerability](https://wordpress.org/support/topic/security-vulnerability-74/)
 *  [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [2 years, 11 months ago](https://wordpress.org/support/topic/security-vulnerability-74/#post-17030467)
 * Hi [@regankhadgi](https://wordpress.org/support/users/regankhadgi/) ,
 * Thanks for actioning this so promptly, we are rolling out the update and we can
   see Wordfence are now showing version 1.2.1 as a full patch.
 * Thanks for a great plugin!
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Comments Like Dislike] Security Vulnerability](https://wordpress.org/support/topic/security-vulnerability-74/)
 *  [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [2 years, 11 months ago](https://wordpress.org/support/topic/security-vulnerability-74/#post-17019425)
 * Hello r@regankhadgi,
 * Please note that Wordfence are reporting that you have only partly resolved the
   issue. A nonce is not sufficient, you need to check the capabilities of the user
   to ensure they should be allowed to reset the plugin (using current_user_can(‘
   manage_options’ ) or similar).
 * Can you fix and release a new version?
 * Many thanks.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[ACF Content Analysis for Yoast SEO] High Number of ‘query-attachments’](https://wordpress.org/support/topic/high-number-of-query-attachments/)
 *  Thread Starter [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [8 years, 9 months ago](https://wordpress.org/support/topic/high-number-of-query-attachments/#post-9670635)
 * Hi Thomas,
 * Thanks for the prompt response. We do have image fields used in some of the custom
   field groups.
 * We have implemented the function you have provide and it does seem to have had
   a positive impact, when testing on our staging server (less calls). We will push
   to production and monitor it there and let you know of the outcome.
 * All the best,
 * Julian

Viewing 11 replies - 1 through 11 (of 11 total)