Long Watch Studio - Code Faeries
Forum Replies Created
-
Forum: Plugins
In reply to: [MyRewards] Vulnerability in version 5.4.14Hello,
We have already been notified of this vulnerability (which isn’t really one) by the Patchstack platform researcher who discovered these pseudo-vulnerabilities.
To provide some context, it’s important to understand that Patchstack pays researchers based on the number of vulnerabilities reported. This cross-site scripting vulnerability requires to already have elevated privileges on your site to be exploited. In such way it is anecdotal and cannot be exploited if administrative rights and WordPress roles are properly managed by the admin of the website in question. Anyway, next release will include an update for that.
However, it’s very interesting to report these vulnerabilities since they affect 70% of WordPress and WooCommerce plugins. Unfortunately, this is a lucrative business for these whistleblowers who exploit this opportunity to generate easy revenue. We identified a single day where the researcher in question reported 70 vulnerabilities (always the same XSS vulnerability) in less than 24 hours. You get the idea… It’s a bit like antivirus or anti-malware programs that find false positives to fuel users’ fear of a viral infection, often prompting them to upgrade to the premium or paid version of the product for better security.
Now, if you notice any real practical (not theoretical) exploitation of this vulnerability in our plugins, please let us know, and we’ll immediately send our development team to fix it. However, as it stands, we have not been provided with any evidence that this known vulnerability affects our products.
Sincerely,
Forum: Plugins
In reply to: [MyRewards] Myrewards Social ShareIn MyRewards, customers earn points, not coupons directly. You can decide to turn these points into discount coupons, but that’s independent from other plugins. Therefore, coupons will be cumulated.
Forum: Plugins
In reply to: [MyRewards] Myrewards Social Share- MyRewards doesn’t display anything on product pages, this option is only available in the pro version. Therefore, if you have an option to share something on social media, it doesn’t come from this plugin.
- MyRewards isn’t a review plugin. If you want to manage your review process, either consult the WooCommerce documentation or use the “Customer Reviews for WooCommerce” plugin.
Forum: Plugins
In reply to: [MyRewards] Myrewards Social ShareHi,
The social share isn’t available in the free version. In the free version, there is only the referral feature, not the social share one.
Yes, the review system only works with WooCommerce standard product reviews or with the “Customer Reviews for WooCommerce” plugin. It won’t work with other plugins.
Forum: Plugins
In reply to: [MyRewards] MyRewards (Free Version) few questionsEach order is handled separately. Extra amounts from previous orders are not taken into account
Forum: Plugins
In reply to: [MyRewards] MyRewards (Free Version) few questions2) It only works for products on your website
3) There is an option in the pro version to choose if you want to round to the closest value or not
4) Points expiration is a pro version feature
Forum: Plugins
In reply to: [MyRewards] Myrewards Social ShareThe Social Share feature is part of the pro version WooRewards. We’re not allowed to discuss pro features here. Please look at our documentation for more information
Forum: Plugins
In reply to: [MyRewards] MyRewards (Free Version) one more question about pointsHello,
The user can decide how many points he wants to use on an order
Forum: Plugins
In reply to: [MyRewards] MyRewards (Free Version) few questionsHi,
- On the demo website, it’s the pro version, not the free version. If you order a subscription, the first month is free and you can cancel at any time, leaving you one month to test the features
- We’re not allowed to discuss pro features here. If you want more information, please check our documentation : https://plugins.longwatchstudio.com/kbtopic/wr/
Forum: Plugins
In reply to: [MyRewards] Woorewards PluginHello,
The lws_sponsorship shortcode isn’t available in the free version. It’s a pro version feature. If you’re using the Pro version, please contact us by using the support feature integrated in the plugin or by visiting this page https://plugins.longwatchstudio.com/contact-us/Forum: Plugins
In reply to: [MyRewards] Product Page PreviewHello,
Product page preview is a pro version feature. In the pro version, you can select the location of the information, and it’s indeed based on WooCommerce hooks.Forum: Plugins
In reply to: [MyRewards] Email Notifications on the Free Version of Plugin?Hello,
Earning points and getting a reward are 2 different things.
If your loyalty program is set to give discount coupons when customers get over a set amount of points, then you can set up an email in the free version to inform them that they received the coupon.
However, the possibility to inform customers of how many points they received for an order is a pro version feature.Forum: Plugins
In reply to: [MyRewards] Points for unapproved reviewHello again,
We ran the following test :
- In WooCommerce → Settings → Products : Check “Enable product reviews”
- In Settings → Discussion → Before a comment appears : Check “Comment must be manually approved”
- We then logged in as a customer to post a review. The review was sucessfully held for moderation
- With the admin profile, in Products → Reviews, we manually approved the review
- In WooRewards → Customers, the logged in customer did receive the review points.
We then ran the test again by adding the “Purchase required” limitation.
- For a product the customer never purchased, he didn’t receive points
- For a previously purchased product, he received points
The other test case where the customer can’t receive points is if he already received points for reviewing this product (products can only be reviewed once)
Forum: Plugins
In reply to: [MyRewards] Points for unapproved reviewHello,
We will look into it and release an update if we manage to reproduce the error.
Forum: Plugins
In reply to: [MyRewards] Can not locate the Add-ons interface inside the pluginIn the free version, you can send an email to inform customers that they have unlocked a new reward.
I’m not allowed to discuss pro version features in this support forum.
However, there’s no version where you can send an email to tell people they need X more points to get a coupon. Regarding the unused coupon, it’s not available in the free version.