• The members plugin has a lot of dependencies that are vulnurable.
    Here are the critical ones:

    Prototype Pollution in minimist Critical Development
    198 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-block-permissions/package-lock.json Prototype Pollution in minimist Critical Development
    197 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-meta-box-integration/package-lock.json Prototype Pollution in minimist Critical Development
    196 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-privacy-caps/package-lock.json Prototype Pollution in minimist Critical Development
    195 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-givewp-integration/package-lock.json Prototype Pollution in minimist Critical Development
    194 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-edd-integration/package-lock.json Prototype Pollution in minimist Critical Development
    193 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-admin-access/package-lock.json Prototype Pollution in minimist Critical Development
    192 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-acf-integration/package-lock.json Prototype Pollution in minimist Critical Development
    191 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/package-lock.json Prototype Pollution in minimist Critical Development
    190 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-woocommerce-integration/package-lock.json Prototype Pollution in minimist Critical Development
    189 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-block-permissions/package-lock.json Prototype Pollution in minimist Critical Development
    188 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-meta-box-integration/package-lock.json Prototype Pollution in minimist Critical Development
    187 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-privacy-caps/package-lock.json Prototype Pollution in minimist Critical Development
    186 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-givewp-integration/package-lock.json Prototype Pollution in minimist Critical Development
    185 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-edd-integration/package-lock.json Prototype Pollution in minimist Critical Development
    184 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-admin-access/package-lock.json Prototype Pollution in minimist Critical Development
    183 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/addons/members-acf-integration/package-lock.json Prototype Pollution in minimist Critical Development
    182 opened 3 months ago ? Detected in minimist (npm) ? blogs.com/wp-content/plugins/members/package-lock.json Prototype pollution in webpack loader-utils Critical Development
    171 opened 7 months ago ? Detected in loader-utils (npm) ? blogs.com/wp-content/plugins/members/addons/members-block-permissions/package-lock.json

    As you can see, most are known vulnurabilities since 3 months or older. Are there any plans to update the dependencies?

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Author Caseproof

    (@caseproof)

    Hi @kajakske

    Thank you for pointing this out. We appreciate it. I<span class=”prokeys-snippet-text”>’ll?</span>pass this on to our developers and hopefully we can resolve it soon.

    Best

    Thanks for making them aware, my site was hacked this morning due to this plugin

    Plugin Author Caseproof

    (@caseproof)

    I’m sorry to hear that your site was hacked. Did you install Members from Github? We highly recommend downloading Members from WordPress directly and use this official version only.

    Best

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Vulnurabilities in used dependencies’ is closed to new replies.