boardboss
Forum Replies Created
-
Great, thank you.
Can we get an answer about the 24-hour trigger question from your dev team? Do admins have any control over setting the time, is it triggered based on server time (and at what time?), or anything else useful to admins. Thank you.
I waited a bit longer to ensure the process had enough time to clear the erroneous warning, and it appears the warning was successfully removed. It would be nice to know the answer to my previous question about the 24-hour trigger so admins would have some idea of how that process works. Other than that, it appears this issue is resolved. Thank you.
Thank you for the update. Do you know at what time the ‘updated once every 24 hours’ process is triggered? Is it based on some setting in your plugin, server time, or something else?
Thank you for the clarification. I will wait the indicated amount of time and check again. Do you mean the notification should be removed after the next scheduled malware scan? If so, what if an admin does not schedule daily malware scans? Would the notification go away based on some other parameters, or would notification removal require manual syncing with the cloud?
It is now 11:14 UTC, and I just checked the situation on a site where the notification is being displayed. I have taken no action to sync with the cloud, nor any other manual intervention, and the notification is still present. Based on your previous reply, I expected it should have been removed automatically. Or did I misunderstand something?
Yes, I received your reply to my private ticket on your platform. Thank you for the update. I can confirm the ‘sync with cloud’ option removed the warning on the one site I tested. I confirmed the same warning message appears on multiple other sites, and I am waiting until 11:00 UTC today, which is approximately 90 minutes since you replied, before checking those sites again for message removal. I will update here after 11:00 UTC if the ‘within the hour’ resolution works.
I simultaneously raised a ticket with the Post SMTP folks, which is included below, and the response I received from them, included further down:
Ticket text: I received a warning from my security plugin, Security by CleanTalk about the Post SMTP plugin being vulnerable under CVE-2024-13362. However, I cannot immediately confirm that your plugin is affected by this vulnerability. Apparently, CVE-2024-13362 refers to use of Freemius and many, many plugins are therefore affected. Can you confirm whether your plugins are or are not affected, and if affected, what course of action admins should take? Should we disable or uninstall your plugin and find a different solution?
Their response: Thank you for bringing this up.Iβm happy to confirm that this issue has already been addressed and the fix was released in Post SMTP v3.9.1.
The vulnerability report youβre referring to was related to a dependency/shared component, and the necessary remediation has already been applied in the latest release. Wordfence has also acknowledged the patched version accordingly. Here is the link to WordFence report confirming the fix: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/post-smtp
Please update Post SMTP to v3.9.1. (note added by me: all sites flagged by CleanTalk Security already have Post SMTP updated to version 3.9.1)
There is no need to disable or uninstall the plugin as long as you are running the updated version.
If you have any other concerns or would like us to review your setup, feel free to reach out anytime.
My conclusion: It appears CleanTalk Security incorrectly raised an alert in this situation. The warning notice generated by your plugin appears in the plugin list immediately below the Post SMTP plugin. In the warning emails sent from CleanTalk about this issue, the Post SMTP plugin was specifically mentioned. Again, I believe this is inaccurate.
Forum: Plugins
In reply to: [Democracy Poll] Typo in resultsThank you for the reply. Unfortunately, changing text in this way will not solve my problem as only *some* of the text values are inaccurate. For the life of me I have no idea why this is so difficult to resolve. Also, no idea why only some of the text is incorrect. Maybe there was alcohol involved at some point? π
Forum: Plugins
In reply to: [Query Monitor] Is Query Monitor fully compatible with PHP 8.4.x?I guess you assumed everything was okay since you marked the ticket as resolved and did not reply further; however, the problem I reported still existed.
Since I did not hear back from you, I installed your plugin on a different WordPress site running on a different server. The exact same thing happened on that site/server.
I just now noticed that there was an update available for Query Monitor while I was on the second site, so I updated it. Immediately afterward, the problem I described stopped happening.
I then headed over to the site where I originally found the problem and updated Query Monitor. The reported problem no longer exists.
I cannot say with 100% certainty that the update for Query Monitor actually fixed the issue, I only know what happened on the two different sites/servers I tested, and in the case of the first site/server, the 502 error problem has been happening for several days. After the update, the problem stopped.
I agree that this is a strange way for a 502 error to present itself, yet present itself it did. In any case, I am happy the plugin was updated (thanks for that) and I *NOW* consider this problem resolved. I hope the resolution is permanent.
Forum: Plugins
In reply to: [Query Monitor] Is Query Monitor fully compatible with PHP 8.4.x?Thank you for the reply. I ensured FastCGI, Redis Object Cache, and OPcache were disabled. There are no caching plugins installed in WordPress. That should address any caching concerns.
I checked the file NGINX: /var/log/nginx/error.log for any errors. There are only ‘notice’ entries in the log, and none are related to caching, errors, or alerts. If I enable/disable OPcache, then I can see the appropriate entries in the log file related to OPcache.
I also checked the file PHP FPM: /var/log/php8.4-fpm.log for any errors. The only entries refer to notices and seem to correctly reflect when PHP-FPM is enabled and when the PHP FPM workers are reloaded.
Do you have any other suggestions? I can try earlier PHP versions all the way back to PHP 7.0.x; however, I would rather not try older PHP versions except as a last resort.
I understand what you are saying about a 502 error. That said, I find it very odd that a 502 error ONLY occurs as I described above when interacting with your plugin. Is there anything you can think of as far as your plugin contributing to a 502 error?
If you do not, I may go ahead and try to install your plugin on another VPS running the same stack and WordPress to see if the results are the same.
Forum: Fixing WordPress
In reply to: Trying to understand the update process for pluginsThank you for your reply. Traffic should not be an issue on the site in question, as it gets visited around the clock. I installed the Cron Logger plugin, although it has not been updated in 9 months and is untested with the current version of WordPress. It shows two updates pending, which happen to reflect the currently-installed version and the available version update to be the same, and is scheduled for approximately 12 hours from now, so I will see what happens in the morning.
Again, thank you for the tip about cron logging.
Forum: Plugins
In reply to: [Democracy Poll] Typo in resultsAfter a surge in votes I noticed now that the top two votes now say “vote” and not “votes” (see the link for screenshot). I cannot find where to change this, but it is an annoying bug.
Thank you for your reply. It makes sense that you would follow the way WooCommerce handles single variations. I doubt Automattic is going to do anything about this, as clean and lean code does not seem to be their priority.
I read the instructions you provided. If there is only one single amount for all gift cards, why should a user have to jump through any hoops to select it as a default amount? Shouldn’t a single value be selected as default by, well, default? Or was that overlooked during the development process?