{"id":19027790,"date":"2026-09-23T21:29:29","date_gmt":"2026-09-23T21:29:29","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=topic&#038;p=19027790"},"modified":"2026-09-23T21:47:14","modified_gmt":"2026-09-23T21:47:14","slug":"xss-vulnerability-81","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/xss-vulnerability-81\/","title":{"rendered":"XSS Vulnerability"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Patchstack and Wordfence are both reporting CVE-2026-57417 as patched in Cart Lift 3.1.58, but 3.1.58 does not yet appear to be available through WordPress.org, where 3.1.57 is currently the latest version.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Could you confirm whether 3.1.58 is scheduled for release, and whether users should deactivate Cart Lift until the security update is available?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thank you.<\/p>\n","protected":false},"template":"","class_list":["post-19027790","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19027790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19027790\/revisions"}],"predecessor-version":[{"id":19027796,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19027790\/revisions\/19027796"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19027790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}