Hi @yosmc, thanks for your suggestion.
“A plugin has an update available” is already a medium severity alert, with high and critical levels above it. However, if the version you currently have installed has a known vulnerability then that’ll be upgraded to critical. The full list of severity levels and what falls under each level is available here, so that you can set alerts appropriately for your needs: https://www.wordfence.com/help/dashboard/alerts/
Naturally if you’ve received an email where the above block reason is miscategorized, please forward it to wftest @ wordfence . com and let me know here once you’ve sent it so I can take a look. Putting your forum username in the subject line will help us find it.
Many thanks,
Peter.
Thread Starter
yosmc
(@yosmc)
Thanks for the clarification. The message I received reads as follows:
Critical Problems:
- The Plugin xyz needs an upgrade (1.2.3 -> 1.2.4).
Update includes security-related fixes.
Vulnerability Severity: 6.4/10.0 (Medium) Vulnerability Information
https://ww.wp.xz.cn/plugins/xyz/#developers
9 existing issues were found again and are not shown.
There are two things I find confusing:
- I received a critical alert because of a medium vulnerability (in this case, storerd cross site scripting by contributors on a site that doesn’t allow for contributors and that doesn’t even have the plugin activated). Of course it would be best to receive critical alerts for vulnerabilities only that pose an actual threat to my site(s). So I’m wondering about the threshold – will I receive critical alerts for plugin updates with “low” vulnerability severity as well?
- If the alert is set to critical only, imho I should not be told how many existing issues were found again, but rather how many critical issues were found again (if any). To me, security alerts are only as useful as the time they save: I am alerted so I don’t have to check myself. But if the alerts suggest that I might have overlooked something, the usefulness diminishes – first time I will go and check, second time I might ignore the message altogether, which defeats the purpose of receiving such alerts in the first place.
-
This reply was modified 1 year, 9 months ago by
yosmc.
-
This reply was modified 1 year, 9 months ago by
yosmc.
-
This reply was modified 1 year, 9 months ago by
Yui.