Viewing 7 replies - 1 through 7 (of 7 total)
  • Do you mean all of WpTables?

    I can confirm that it flags up both the old premium version prior to 3.4.2, as well as the free version available via wordpress repo.

    Update to version 3.4.2, or a newer patched version

    https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdatatables/wpdatatables-341-improper-access-control-leading-to-table-permission-takeover

    Thread Starter yesemenova

    (@yesemenova)

    Current Plugin Version: 2.1.47

    This is the last version that is available for download in WordPress.

    https://www.ads-software.com/plugins/wpdatatables/

    I am seeing the same thing. Why has this not been updated on wordpress but if you Buy the PREMIUM version it is up to version 5.1????

    Plugin Author wpDataTables

    (@wpdatatables)

    Hello,
    The vulnerability was found in the full version of wpDataTables v3.4.1, so all premium versions before that can be affected.

    Lite version does not have these functionalities (such as SQL based tables),
    so Lite version was never affected.
    Those reports are not related to the Lite version, but they can be reported in the lite version because the resources where this information about themes or plugins vulnerabilities are stored are generated by the theme or the plugin slug. Those slugs are the same in both lite and the full version, and because of that, you get those notifications.

    The important thing is that there’s nothing to worry about. Newer versions of the wpDataTable premium don’t have these issues, ( the latest one is 5.1)

    and Lite versions never did.

    Unfortunately, until wpDataTables Lite goes above version 3.4.2 these reports will indicate a false positive. The lite and the full version have the same slug (wpdatatables), and that’s why the security plugins can’t differentiate between the versions.

    I hope this helps, do let us know if you need any further assistance.

    Thanks. That does clarify things. Love WpTables.

    Plugin Author wpDataTables

    (@wpdatatables)

    Hello, @kamsites
    You’re welcome, we are happy to advise.
    Please don’t hesitate to reach out to us whenever you have any questions about the plugin and we will be happy to answer.
    Kind regards.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘The Plugin “wpDataTables – has a security vulnerability’ is closed to new replies.