Authenticated (Contributor+) Stored Cross-Site Scripting
-
I’ve received a report from Wordfence that this plugin (version <=3.5) has a vulnerability on sites where accounts (contributor+) can place unwanted content.
Sources:- https://www.wordfence.com/threat-intel/vulnerabilities/id/60af0a7c-014b-4f71-9918-7ddc1186bee4?source=plugin
- https://patchstack.com/database/vulnerability/addons-for-visual-composer/wordpress-livemesh-addons-for-wpbakery-page-builder-plugin-3-5-cross-site-scripting-xss-vulnerability
Are you aware of this issue and can we expect a fixed version soon?
Thanks!
Viewing 5 replies - 1 through 5 (of 5 total)
Viewing 5 replies - 1 through 5 (of 5 total)
- The topic ‘Authenticated (Contributor+) Stored Cross-Site Scripting’ is closed to new replies.