• Resolved mike.s

    (@mikes-1)


    Im getting a security alert popup on all my clients sites and its causing them worry as they think their website is not secure:

    SECURITY ALERT: Insecure WordPress version detected. Your site is running WordPress version 4.7.4, which has 1 known security vulnerabilities. You should upgrade WordPress as soon as possible. More Information

    which links to this page – https://wpvulndb.com/wordpresses/474

Viewing 7 replies - 31 through 37 (of 37 total)
  • Steve

    (@stevejohnson)

    This WP vulnerability issue you mention – “We were surprised to see that they did not patch that issue.” Did you submit a patch for it?

    WP is, after all, a community effort.

    I came here because I am experiencing exactly the same issue on a couple of sites – the client is all up in arms about ‘security warnings’.

    ‘Flaming you’ helps if it awakens you to the fact that people don’t want to be bombarded with Chicken Little warnings all the time and give them an option to turn them off.

    Plugin Contributor redsand

    (@redsand)

    Hi @stevejohnson,

    This WP vulnerability issue you mention – “We were surprised to see that they did not patch that issue.” Did you submit a patch for it?

    They already have had a ticket for this for a long time, and are fully aware of multiple methods to mitigate the issue. There was an article about that in WP Tavern. It just was not a high priority. It’s easier to exploit than people realize though. All security exploits should be taken seriously.

    WP is, after all, a community effort.

    Yes, we’re quite aware of that. ?? Been an active part of the WordPress development community for over a decade, and am a core contributor.

    ‘Flaming you’ helps if it awakens you to the fact that people don’t want to be bombarded with Chicken Little warnings all the time and give them an option to turn them off.

    Absolutely not. Nope. No matter what the situation or context, flaming is never the right way to handle things. There is big a difference between “flaming” and honest, constructive criticism.

    We always have emphasized security and have educated users on security issues, and always will. That’s not going to change even if people do flame us. What people don’t realize is that for every one person that does, there are 100 more that are happy about our emphasis on security and thank us for that. So that’s just not constructive. (Besides, several of us are combat veterans, so that kind of thing doesn’t really faze us.)

    If people want to submit a support request, and use our support system the right way, they’re welcome to. We provide outstanding support. Flaming tends to only happen in forums. When people communicate directly with us, things get resolved quickly, and everyone is happy.

    Also, you might want to check your facts before you criticize devs. This thread was already old when you posted this, and there already was an option to disable the security alerts. Another example of why it’s better for people to come directly to us. ??

    If you need any further help in the future, just contact us directly using the WP-SpamShield Support page…that’s how to get the best info and get things resolved quickly.

    – Scott

    Hi,

    I get the same alert, saying my site (https://sunlog.ro/) is running WordPress version 4.7.5, which is vulnerable.

    My site, however, is runing WordPress 4.8.

    Plugin Contributor redsand

    (@redsand)

    The alert displays the current version of WordPress installed, as reported by WordPress itself. If you’re using the latest version, it would not be triggered at all. Please be sure you’re using the most up-to-date version of the plugin.

    Any tech support issues should be directed to the WP-SpamShield Support page.

    Everything is updated. WP-SpamShield Version 1.9.13.

    I made a screenshot:

    Screenshot

    The alert says WP 4.7.5. Down at the footer, we have: “Thank you for creating with WordPress Version 4.8”. Didn’t think I actually need to offer a proof.

    Anyway, this was a one time alert only; it’s not showing anymore.

    Plugin Contributor redsand

    (@redsand)

    @ethos,

    If you see the X in the top right corner, click that to close the admin notice, and it will be gone forever. If that popped up before you upgraded, and you never closed it, then just close it and it’s gone.

    Please see my previous post:

    Any tech support issues should be directed to the WP-SpamShield Support page.

    We don’t do our tech support through the forums here…so please don’t post pics or data here regarding issues. All of our tech support is done through our site, as it offers a better user experience, and we have a number of resources for our plugin users that are not available here (including translations and better privacy/security for users).

Viewing 7 replies - 31 through 37 (of 37 total)
  • The topic ‘security alert’ is closed to new replies.