• Resolved skylight

    (@skylight9345)


    Hosting sites are still showing this warning and suggest removing the plugin. Is it solved yet?

    The page I need help with: [log in to see the link]

Viewing 5 replies - 1 through 5 (of 5 total)
  • This vulnerability is about https://ww.wp.xz.cn/plugins/admin-menu-restriction/ plugin, not this one.

    Plugin Author Janis Elsts

    (@whiteshadow)

    Nazar Hotsa is correct – that vulnerability report is about a different plugin.

    Sorry for not responding sooner! For some reason, I didn’t get a notification about this thread.

    Thread Starter skylight

    (@skylight9345)

    Hostinger hpanel was showing that alert about my Admin Menu Editor plugin and suggested immediate removal. Same thing was suggested by Wordfence Security – Firewall & Malware Scan which is reputed as far as I know. Could you please check?

    Plugin Author Janis Elsts

    (@whiteshadow)

    I already looked into this shortly after the report first came out – a few other users contacted me about it.

    The report that you mentioned has a link to the affected plugin. Scroll down to the “References” section and click the “Plugin page” link. You will see that it goes to a different plugin that just happens to have the same name.

    Unfortunately, it seems that various tools just look at the plugin name and don’t bother to check the slug or even the version number. I’m afraid I don’t have the energy to convince every tool developer to update their detection algorithms.

    Thread Starter skylight

    (@skylight9345)

    Thanks

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Cross-Site Scripting (XSS) vulnerability’ is closed to new replies.