critical CVE in used includes?
-
Hi,
scanned my WordPress installation using the OWASP Dependency-Check (https://owasp.org/www-project-dependency-check/)
The scan showed
CVE-2019-10744 – 9.1 Critical – Prototype Pollution in lodash
https://github.com/advisories/GHSA-jf85-cpcp-j695
found in wordpress/wp-content/plugins/stop-user-enumeration/includes/vendor/alanef/plugindonation_lib/package-lock.json?lodash.templateCVE-2020-28469 – 7.5 High – Regular expression denial of service
https://github.com/advisories/GHSA-ww39-953v-wcq6
found in wordpress/wp-content/plugins/stop-user-enumeration/includes/vendor/alanef/plugindonation_lib/package-lock.json?glob-parentCould you update your dependencies?
Regards,
Christof
- The topic ‘critical CVE in used includes?’ is closed to new replies.