Viewing 7 replies - 1 through 7 (of 7 total)
  • Any status on this? I would hate to have to disable / delete the plugin.

    Unfortunately, I had to deactivate and delete the Related Posts for WordPress plugin today. Last week, WP Engine informed me that this plugin poses a security risk and yet there has not been any patches or updates released by the plugin author.

    Hope this gets resolved soon since it’s a very useful plugin that I’ve used on many sites.

    Here’s the full message from WP Engine:

    At WP Engine we take the security of your sites very seriously, and make every effort to keep our customers aware of any potential security risks. We are reaching out to you today because we identified your site(s) is (are) utilizing a vulnerable version of the Related Posts for WordPress plugin.

    At this time, we are not seeing that the plugin author has released an update or patch for this vulnerability. WP Engine has attempted to reach out to the plugin author to request the timing of a patch. We will report back to you if/when we receive a timeframe for when the author expects to release one.

    WP Engine summary of the vulnerability: Data from an attacker could be interpreted as code by site visitors’ web browsers. The ability to run code in another site visitors’ browser can be abused to steal information, or modify site configuration.

    Original 3rd-party’s report on the vulnerability: Please note that questions related to this article should be directed to the 3rd-party researcher and not WP Engine:
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24482
    https://wpscan.com/vulnerability/2f86e418-22fd-4cb8-8de1-062b17cf20a7

    We encourage you to assess the risk of continuing to use this plugin until a patch is released.

    Plugin Author Barry Kooij

    (@barrykooij)

    I will release a fix for this today. Sorry for the delay on this.

    Plugin Author Barry Kooij

    (@barrykooij)

    A fix for this has just been pushed!

    We have updated our records to reflect that this has been fixed. Thanks.

    Thread Starter kolli

    (@kolli1337)

    Great news, thank you @barrykooij!

    Really great to hear Barry! Very much appreciated. Thanks!

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Vulnerability fix’ is closed to new replies.