Vulnerability report linked to different plugin
-
We have installed the Plugin “GDPR Cookie Consent” by WebToffee. https://www.webtoffee.com/product/gdpr-cookie-consent/ Version 2.5.9. CleanTalk is generating the following warning for this plugin: “This version contains a known vulnerability CVE-2024-3599. Updating the plugin to a version higher than 3.1.0 is strongly recommended. Full report is?here?Have questions? Ask us?here“.
The WebToffee team advises that this looks like a false positive because the vulnerability report is for a different plug. Please see message from WebToffee team below:
“We can see that you are using the Cleantalk plugin to check for vulnerabilities on your site, and we truly appreciate your efforts in keeping your site safe. We want to reassure you that there are currently no vulnerabilities in our plugin. The vulnerability alert shown in the banner is for “WP Cookie Consent (for GDPR, CCPA, and ePrivacy)” by WPEkaClub, not our plugin “GDPR Cookie Consent Plugin (CCPA Ready)” by WebToffee.
?
The message you are receiving might be due to a glitch in the Cleantalk plugin. If you click on the vulnerability report link generated by the plugin, you can see that the report is for “WP Cookie Consent (for GDPR, CCPA, and ePrivacy)” by WPEkaClub. Additionally, you may contact the Cleantalk plugin team regarding this.”Please can you advise next steps and whether our installed plugin contains vulnerabilities or not.
The page I need help with: [log in to see the link]
- You must be logged in to reply to this topic.