• Resolved joeck

    (@joeck)


    We are constantly getting the following notification: “WordPress WP Pipes plugin <= 1.33 – Auth. SQL Injection (SQLi) vulnerability” even though we have updated to v1.4. Is there an issue where iThemes Security doesn’t see the new version number? How can we fix this without muting the notification?

Viewing 4 replies - 1 through 4 (of 4 total)
  • Hi @joeck ,
    I’m sorry to hear this. This will still happen if there are still data remnants of one of the sites. In other words, there is most likely a database table or site still active with the vulnerable plugin or an active iThemes security plugin. 
     
    I’d recommend double-checking old/current server to see if a copy of the site exists. 
     
    Best Regards,
    Shalom.

    Thread Starter joeck

    (@joeck)

    Thanks for your response @shalomt . So right now I am focusing on one specific site. This site has the WP Pipes plugin updated to version 1.4, but twice a day I get an Critical Issue about Vulnerable Software, which states that WP Pipes <= 1.33 has a vulnerability.

    I have screenshots of the plugin version and the iThemes log here: https://imgur.com/a/fDp2W4o

    Let me know if there’s more you need from me to figure out why this is happening.

    Hi @joeck ,

    Thanks for getting back regarding this issue.

    We’ll like you to please proceed with a conflict test. But, first, create a recent backup in case you lose any settings during the trial and have to restore to a previous working state.

    Then deactivate all plugins apart from iThemes Security plugin and WP Pipes, clear all caches and check again if the issue is still there. If not, it means that something is conflicting, so start activating the remaining plugins and theme, one by one this time, checking every time for the reported issue until you reproduce the problem, thus finding the conflicted combination.
    The following can assist you during this test: https://help.ithemes.com/hc/en-us/articles/115003073433-Checking-for-a-Conflict-.

    Alternatively, I’ll suggest a fresh installation of the iThemes Security plugin.

    Please let me know if this helps.

    Best regards,
    Shalom

    Hi there,
    I hope the information provided helped resolve your issues. Given that we have not received a response, I will mark this post as resolved. If you still need some assistance, please feel free to open a new support topic, and we would be happy to assist.
    Thank you!

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Vulnerable Software Notification not seeing updated plugin version’ is closed to new replies.