• Resolved LN-CWM

    (@ln-cwm)


    Why has this plugin been removed from WordPress? My Wordfence security plugin is indicating a “critical” vulnerability. What’s the story? Has the plugin been abandoned?

    Advice appreciated. Do I need to find another plugin to do this job?

    The page I need help with: [log in to see the link]

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author A. Jones

    (@nomadcoder)

    Hello. I apologize for any inconvenience. Although there are no future enhancements planned to the plugin, we do want to keep it updated and secure for current uses and have no intention of abandoning the plugin without notifying users here in the support forum.

    The plugin has not been abandoned and should be back online today.

    There has been a push by volunteers to identify potential security issues which get reported to security apps like Wordfence.

    The issue has been fixed. While it’s inconvenient, It is entirely for your benefit! We do not think that the vulnerability was critical but it related to a feature added that allowed html to be used in the description field. This would have allowed bad actors to inject scripts.

    Please update your plugin.

    If you wish to switch to another free plugin, we should be able help you to convert.

    Thread Starter LN-CWM

    (@ln-cwm)

    Thanks, A. Jones, for your helpful response. Alas, Wordfence is still reporting a critical vulnerability “in all versions up to, and including, 4.34 due to insufficient input sanitization and output escaping on user supplied attributes.” I’m not particularly keen on switching to a new plugin, free or paid, but I remain a tad nervous. I would certainly consider a reasonable yearly subscription fee for this plugin.

    Thread Starter LN-CWM

    (@ln-cwm)

    I would also note that, on the WordPress plugin page for (Simply) Guest Author, the text under the heading says “version 4.35.” However the version number in the right border still says 4.34. I tried downloading and installing the zip file, and got a warning that I was about to install 4.34 over the same version, 4.34.

    Plugin Author A. Jones

    (@nomadcoder)

    Thank you for letting me know. I will look into this.

    Plugin Author A. Jones

    (@nomadcoder)

    This should be fixed. If you want to email me, I will send you a copy of the report. [email protected].

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘“This plugin has been closed”??’ is closed to new replies.