Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author shehabulislam

    (@shehabulislam)

    Hi

    I’m sorry, but that is incorrect information. We did not use Freemius SDK in this plugin and we have updated the Freemius SDK in all our plugins where it was used.

    Thank you

    Hi,

    I’m having vulnerability issues with the plugin. This is the message I get:

    WordPress PDF Poster – PDF Embedder Plugin for WordPress plugin <= 2.0.11 – Reflected Cross Site Scripting (XSS) vulnerability

    What Actions Should I Take?Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked. Either quickly update the vulnerable theme, plugin or WordPress version immediately to the newest version or immediately deactivate and delete the plugin or theme from your WordPress installation until a fix is available.

    @mdtareqhassan @suzannap sorry for this, it’s a false-positive indication. We marked those database entries as non-published for further investigation. The problem is that some plugins had specific tags that are indicating usage of Freemius WordPress SDK. There are about 1,5K plugins/themes that are using Freemius so purely manual inspection is not an option, and as we see now automatic identification might give some wrong results. Once again sorry for the mess, we just trying to make the WordPress ecosystem safer and help the community. Thank you for letting us know about the error ??

    So will there be a solution or should I just get rid of the plugin?
    I just got another report with critical issues and the same message

    Plugin Author shehabulislam

    (@shehabulislam)

    Hi @suzannap

    I am sorry, but how can we fix the issue if it’s not related to this plugin? The issue is happening in Freemius SDK, and we didn’t use Freemius SDK in this plugin.

    Thank you

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Vulnerability issue’ is closed to new replies.