Im being notified of a new vulnerability?
FluentCommunity (Plugin)
WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability.
| Severity: |
|---|
| MEDIUM |
Affected versions:Β <= 2.7.5
Has anyone else been notified?
Not sure from where you got this notification but we did review our plugins every month, and last month (July), we hired an external auditor + AI reviews, and improved edge case data sanitization and escaping.
Our last release was 16 days ago. Would you please let me know from where you got the notification?
Update: We released a hot-fix: https://community.wpmanageninja.com/portal/space/community-meta/post/fluentcommunity-2-7-7-is-now-available
Shaun Smith-RobertsΒ Shahjahan JewelΒ I've got it as well on today because Fluent Community 2.7.5. My Solid Security alarmed me.
FityircΒ Did not get any notification from Patchstack. Contacting with them.
Shahjahan JewelΒ also got a notification
Manuel MΓΌllerΒ Yes, they all use patchstack. We are in touch with patchstack and releasing an update in an hour.
FityircΒ Released a new version with the fix: https://community.wpmanageninja.com/portal/space/community-meta/post/fluentcommunity-2-7-7-is-now-available
Shahjahan JewelΒ thank you for acting so quickly