Viewing 8 replies - 1 through 8 (of 8 total)
  • Plugin Author Imagelinux4me2

    (@linux4me2)

    Hi Brigitte,

    Thanks for letting me know. I was not aware of this.

    According to the link you provided, the issue is a cross-site scripting vulnerability that “makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.”

    If I understand that correctly, it means that in order to take advantage of the vulnerability, the attacker would have to be someone with login credentials as a contributor or higher for the site. As long as you trust all the users for the site with contributor or higher access, it seems like it would be safe to continue using the plugin until I investigate further and (hopefully) release a patch.

    If you have any doubts about the users of the site with such access, I recommend disabling and deleting the plugin until I have released a fix.

    I will post back here with my progress.

    Thread Starter ImageBrisch

    (@brisch)

    Thanks! So far, on the website I use it, there are no other users. But I am looking forward to the update.

    Blessings, @brisch

    Plugin Author Imagelinux4me2

    (@linux4me2)

    @brisch, that sounds like you’ll be safe for now!

    I’m about 75% of the way through a re-do of the PHP files to bring them up-to-date with WordPress best-practices. After that, I’ll check the JS files and do some testing/debugging before uploading an update. I’ll let you know when I’ve got the update uploaded.

    Thread Starter ImageBrisch

    (@brisch)

    πŸ’ – Thanks!

    Plugin Author Imagelinux4me2

    (@linux4me2)

    Hi @brisch,

    I just uploaded v. 1.4, which I believe addresses all the potential security issues reported by Wordfence and brings the code of Menu In Post up to current WordPress guidelines.

    I made a lot of code changes, so although I tested it and debugged it, please let me know if I missed anything.

    Thank you again for making me aware of the security vulnerabilities.

    Thread Starter ImageBrisch

    (@brisch)

    Thanks, I did all updates and it works like before!
    https://thedancingwolves.at/tanzbeschreibung-l/

    Blessings! @brisch

    Thread Starter ImageBrisch

    (@brisch)

    PS: Sorry, I can’t add a five-star rating now. I wanted t do that, but I just saw, I already did it 2 years ago.

    Plugin Author Imagelinux4me2

    (@linux4me2)

    I’m glad it’s working for you. I appreciate the five-star rating. One is enough! Thanks again for letting me know about the security issue(s).

Viewing 8 replies - 1 through 8 (of 8 total)

You must be logged in to reply to this topic.