Viewing 3 replies - 1 through 3 (of 3 total)
  • @bvm, the information is correct. It is low severity, and the attacker needs to have contributor+ authentication.

    The vendor has been ignoring the report since 2025-05-26 (15:01:46 EEST), when it was successfully submitted via the contact form on the vendor’s website.

    Plugin Author Chad Butler

    (@cbutlerjr)

    The vendor has been ignoring the report since 2025-05-26 (15:01:46 EEST), when it was successfully submitted via the contact form on the vendor’s website.

    Some clarification on that report: the screenshot they provided me indicates it was through the contact form on butlerblog.com where it very clearly states the following:

    Before using this form, please note the following:

    WP-Members is supported by rocketgeek.com. If your question or comment has anything to do with WP-Members, do not ask it here.

    Patchstack did not report this through rocketgeek.com, which has been the sole supporting source for this plugin since 2012, and thus, I was completely unaware of this until this morning. Needless to say, I am more than just a little upset about it.

    Could you please respond to my original email with information so I can address this going forward? I don’t want to get into a public argument about who did what here and who is at fault – I’d rather just get it addressed and fixed.

    • This reply was modified 11 months, 2 weeks ago by Yui.
    • This reply was modified 11 months, 2 weeks ago by Chad Butler.

    We were not seeking support – we reported a vulnerability. We always disclose such findings directly to the author, not to any third party offering support or related services. It is up to the author to share this information with others if needed. We avoid involving third parties to minimize the risk of spreading sensitive information to unauthorized persons.

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Reported Vulnerability’ is closed to new replies.