Forum Replies Created

Viewing 5 replies - 1 through 5 (of 5 total)
  • Thread Starter feetfirst

    (@feetfirst)

    Thank you

    I will send an email now

    Thread Starter feetfirst

    (@feetfirst)

    Hi salonbooking,

    My reply to you was placed in moderation by this WordPress forum. So, unfortunately you won’t have seen it and I know you will want to help.

    In summary, I am using the latest version of salon booking 3.40. This is the free plug-in installed last week.

    I am also using the latest version of WP 5.4.2 with Jetpak.

    I have just checked site health and my site passes all tests. Everything is 100% up to date and healthy.

    The issue is that somehow, someone is able to create a “fake booking” in a way that the system does not allow on the booking screen front end or in the backend as an administator.

    For example the fake booking I flagged yesterday is for no service selected, whereas this is a mandatory field on the booking form.

    Thanks for looking into this.

    Ps: If you need more info, pls let me know!

    Thread Starter feetfirst

    (@feetfirst)

    Why has my reply been “held for moderation by our automated system and will be manually reviewed by a moderator”?

    I have just received a message from the plug-in author and yet they will not now be able to respond.

    I cannot understand why you have flagged my last message for moderation. I am not a “bot”, this is not spam and the link in the message is only to the page with the issue.

    Can you please unblock this so that the plugin author can see the details requested which are in my reply and resolve the issue flagged?

    Thanks

    Thread Starter feetfirst

    (@feetfirst)

    Hi salonbooking,

    Thanks for coming back regarding this potential vulnerability in your plug-in.

    I am using the latest version of salon booking 3.40. This is the free plug-in installed last week.

    I am also using the latest version of WP 5.4.2 with Jetpak.

    I have just checked site health and my site passes all tests. Everything is 100% up to date and healthy.

    The issue is that somehow, someone is able to create a “fake booking” in a way that the system does not allow on the booking screen front end or in the backend as an administator.

    For example the fake booking is for no service selected, whereas this is a mandatory field on the booking form.

    I am really worried that someone has hacked the plug-in and potentially my site!

    There would be no value for the hacker, if this is what has happened, because I do not take payment at the time of booking nor do I allow clients to create an account through the website.

    The only page active for use through the plug-in is https://feetfirstreflexology.org/booking/

    Please help me to understand what is happening here, whether this is a security risk and what I/you should do next to fix this issue.

    Thanks and regards,

    Feetfirst

    Thread Starter feetfirst

    (@feetfirst)

    Thanks Simon

    I can’t see any responses to solve the issue highlighted in that thread https://ww.wp.xz.cn/support/topic/random-empty-bookings-bug/

    My concern is that this is not a bug but a malicious attack.

    After all, it is only through the backend that you can over ride the system settings

Viewing 5 replies - 1 through 5 (of 5 total)