• Hey there,

    Just got an notification about the webhost about a vulnerability in the plugin.

    WordPress Amr Shortcode Any Widget plugin <= 4.0 – Contributor+ Stored XSS vulnerability

    Any chance for an update?

Viewing 10 replies - 1 through 10 (of 10 total)
  • ZLC

    (@kindnessville)

    Same concern. Jetpack just found a vulnerability with this plugin and will delete it. I’m leaving this comment here because I want an answer to Niko’s question too.

    Over in the Norwegian theme extension page this comment is posted….

    **This expansion has been closed as of January 19, 2023 and is not available for download.?The closure is temporary, pending a full review**

    My policy with this sort of event is simple, despite the hassle it causes I disable the plugin immediately and delete after 24 hours if a patch has not been issued.

    Has anyone found a good alternative to switch to?

    I can find no replacement. Tagging in here to be notified if anyone gets any new information. Thanks.

    ZLC

    (@kindnessville)

    I immediately disabled and deleted the amr plugin.

    Then I found and installed this plugin: Content Blocks (Custom Post Widget)

    I used another plugin, Better Search Replace, to find all the shortcodes created by amr and replaced them with the new shortcodes generated by Content Blocks (Custom Post Widget).

    The only instance in which Content Blocks (Custom Post Widget) was not helpful was when I specifically needed a widget to be put on a page or post. Otherwise, this plugin worked like a charm for me.

    I hope my answer is helpful to someone.

    Has anyone found an alternative?
    Custom Post Widget doesn’t work for me ??

    • This reply was modified 2 years, 1 month ago by Diogenes.

    It is not prudent to have this plugin active any longer.
    I have deleted it and will work around its former usage

    I also use the plugin and am looking for an alternative. If anyone has anything please let me know. thanks

    Since I make extensive use of this plugin, I hope any issues get resolved and the plugin is made available again.

    Hey guys. If you need latest news/posts replacement that works with shortcode like i did: Recent Posts Widget Extended By Ga Satrya. Just install the plugin and then read the shortcode explanation and add shortcode arguments you need. Can be used on page/post/wp block. Unfortunately didn’t find anything that shortcodes all plugins like amr did. I used to use Resent post extended with thumbnails + amr. Hope this helps someone.

    • This reply was modified 2 years, 1 month ago by jahher.
Viewing 10 replies - 1 through 10 (of 10 total)
  • The topic ‘XSS vulnerability’ is closed to new replies.