• Resolved njomza

    (@njomza)


    Hi,

    I think your plugin, has a “hole”, cause my site was down, because of an IP who has found a hole in the Events Manager. Please send me an email and I’ll send you the tracks I found in my logs.

    • This topic was modified 9 years, 5 months ago by njomza.
Viewing 7 replies - 1 through 7 (of 7 total)
  • Hi,

    Please contact us via the form below. Thanks.

    http://wp-events-plugin.com/contact-us/

    Plugin Author Marcus (aka @msykes)

    (@netweblogic)

    I’ll make sure I keep an eye out for it.

    Thread Starter njomza

    (@njomza)

    The problem is that I needed to attach a photo for you to see the problem and don’t want to be public for security reason… anyway, I’m trying to explain you here: I see something like this in my logs:
    “GET page/125/?ajaxCalendar=1&mo=3&yr=2017%E2%8C%A9%3…

    maybe you could fix the problem.

    Thread Starter njomza

    (@njomza)

    so delete this when you see an email.

    Thanks

    Plugin Author Marcus (aka @msykes)

    (@netweblogic)

    we can’t delete this, please don’t post more stuff here, although the above line isn’t a risk unless you’re running a very outdated version of the plugin.

    I’ll reply to your email when I receive it and you can reply with an attachment, or alternatively send directly to security @ wp-events-plugin.com (no spaces)

    Thread Starter njomza

    (@njomza)

    Of course, I’m running the latest version of plugin. Ok I’ve sent you an email to [email protected].

    Plugin Author Marcus (aka @msykes)

    (@netweblogic)

    Thanks, I’ve replied requesting more information, as I’m still not able to reproduce an exploit. Let’s keep the conversation via email and I’ll conclude our findings here afterwards for posterity.

Viewing 7 replies - 1 through 7 (of 7 total)

The topic ‘Attacks through Events Manager’ is closed to new replies.