• I got got notification about the plugin being vulnerable to attack and wondering if there is a fix/update to patch the security issues in the plugin.

    20+ of my client sites use this plugin with Callrail services, but if a fix can’t be made soon, I will have to encourage my clients to use another service. Not what I want to do as Callrail works perfectly, just need to get the plugin patched.

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author lauracallrail

    (@lauracallrail)

    Hi @stapolin We’re aware of the issue that’s been flagged and we’re working on releasing a patch as soon as possible.

    One of my sites has got hacked so far and I got a notice from Google that malicious software was detected and the client’s Google Ads got disapproved. I have the plug-in installed on probably 15+ other sites as well.

    Plugin Author lauracallrail

    (@lauracallrail)

    CallRail has identified a vulnerability in our WordPress plugin, with a low classification of exploitability (1.6 on the CVSS scale). This vulnerability requires an admin user at your organization to take action (such as clicking a button on an attacker controlled website) to execute. We are working as quickly as we can to get this issue resolved, and expect to have a fix published in the next week. In the meantime, you may continue to use your CallRail WordPress plugin, but we recommend being vigilant about the sites you visit and the links you click, specifically links sent to you from unexpected sources. Logging out of WordPress after performing administrative tasks will provide complete protection from the vulnerability. We apologize for any inconvenience.

    Thread Starter stapolin

    (@stapolin)

    @lauracallrail Thank you for the update.

    Plugin Author lauracallrail

    (@lauracallrail)

    Hi @stapolin This is addressed in version 0.4.10, please update as soon as you’re able to. Thank you!

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Vulnerability Fix’ is closed to new replies.