• I recommend NOT using this plugin and if you use it already, please REMOVE it immediately. The plugin developers simply don’t take security vulnerability issues seriously.

Viewing 6 replies - 1 through 6 (of 6 total)
  • Hi
    We understand that this problem exists, However we are continuously sending our version for testing to concerned WP scan team. Once approved, This shall be released.
    Please check the updated version here:https://github.com/wpeventmanager/wp-event-manager/tree/3_1_42

    Regards,
    Priya

    Thank you for the patient and co-operating with us. Sometime some issues take times to figure out it and testing so sorry for the delay and inconvenience and we are here to help you and fix it.

    We have released new version with fixed so kindly please download it and Let us know if still any problem.

    Kindly please reach us if you have any problem.

    Regards

    WP Event Manager Team

    Thread Starter iNasser

    (@inasser)

    Thank you for your reply

    Are you sure the security vulnerability is fixed with the latest update?

    WordPress WP Event Manager Plugin <= 3.1.42?is vulnerable to Cross Site Scripting (XSS)
    https://patchstack.com/database/vulnerability/wp-event-manager/wordpress-wp-event-manager-plugin-3-1-39-cross-site-scripting-xss-vulnerability

    Plugin Support wpemhelp

    (@wpemhelp)

    Hello,

    Our developers are working on it. We will release the updated version as soon as possible.


    Regards,
    Jathin.

    Plugin Support wpemhelp

    (@wpemhelp)

    Hello,

    Thank you for your patience and co-operation. Some issues take time to figure out and needs to be tested. We are sorry for the delay and inconvenience and we are here to help you and fix it.
    We have released new version with the fix , kindly download the updated version and Let us know if you are facing any problem. Please reach out to us if you face any problem.

    Regards
    WP Event Manager Team

    Plugin Support wpemhelp

    (@wpemhelp)

    Hello,
    ?@inasser
    We’d like to inform you that we have released v.3.1.43?this has no issues with the security. Please install the latest version.

    Regards,
    Wp Event Manager.

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Security vulnerability not fixed for months!’ is closed to new replies.