Home › Forums › Weaver Xtreme Theme › 3 Vulnerabilities patched in Weaver Xtreme Theme Support Plugin
- This topic has 4 replies, 4 voices, and was last updated 2 years, 2 months ago by
Weaver.
-
AuthorPosts
-
June 15, 2024 at 02:25 UTC - Views: 29 #74715
Patti
ParticipantI have the WordFence plugin installed on all of my sites. It’s helped keep hackers at bay without me having to code the sites myself. I received an email today that said that your Weaver Xtreme Theme Support Plugin has 3 vulnerabilities & that they could allow hackers into my site. Before I deactivate the plugin (which would potentially render my Weaver Xtreme theme inactive?) I thought I’d ask you what I should do? I am attaching a screenshot of their 3 vulnerabilities.
June 15, 2024 at 04:41 UTC - Views: 27 #74716User
ModeratorJune 15, 2024 at 12:36 UTC - Views: 18 #74717This reply has been marked as private.June 15, 2024 at 15:34 UTC - Views: 15 #74720scrambler
ModeratorMay be I am understanding that wrong, but the report below shows the vulnerability as patched
Weaver Xtreme Theme Support (wordfence.com)
I have wordfence and the plugin within my site does not report any issue with the Xtreme Theme support
@weaver, any feedback on that?June 15, 2024 at 16:39 UTC - Views: 14 #74723Weaver
KeymasterI’m surprised and disappointed with WordFence. They do a great job if finding very obscure vulnerabilities, and report them to the developer. But their guidelines to the developers indicate that if the problem is patched within a very narrow time frame, they won’t unnecessarily alarm users with what are essentially false reports.
If you look at the report you got, you will notice that all of the reports have the “Patched” status.
The vulnerabilities all were related to just some of the Weaver Xtreme shortcodes that allowed a site member with Contributor or higher admin privileges to enter Javascript code. So sites were always safe from visitors. And the only access is on sites with active Contributors or Authors, which is likely a tiny fraction of sites.
But the holes have been patched, so just be sure you have the latest version of the support plugin. (It is not actually necessary for the main theme to function – the theme support plugin mostly provides some widgets, shortcodes, and the legacy admin interface.)
-
AuthorPosts
- You must be logged in to reply to this topic.

