Forum Replies Created

Viewing 12 replies - 1 through 12 (of 12 total)
  • Thread Starter omnisity

    (@omnisity)

    Hi Cédric,

    Thanks for the clarification.

    Sorry if my original post wasn’t clear. The affected sites are running Slider Revolution 6.7.55 (SR6), not SR7.

    Wordfence is currently flagging the following vulnerability against those installations:

    “Slider Revolution <= 7.0.9 – Unauthenticated Sensitive Information Exposure via sliders/stream”

    However, based on the changelog you linked, it appears the underlying issue was already patched in the SR6 branch in version 6.7.54.

    Can you confirm whether Wordfence may currently be matching this vulnerability against SR6 installations incorrectly, resulting in a false positive for sites running 6.7.54+?

    Thanks again.

    omnisity

    (@omnisity)

    Thanks for clarifying, we’ll pass on this info to our client!

    omnisity

    (@omnisity)

    Thanks for the info, we’ll reach out to the host, it only effects orders that have refunds applied. I’ve attached some images, showing the refund amount and the invoice (which doesn’t show the new amount)?
    https://ibb.co/SDj9Pt71

    https://ibb.co/vvmt9k4Z

    omnisity

    (@omnisity)

    Hi, I’m getting the same error. We’re using Object Cache pro, disabling it, removes the error and the PDF now loads, but none of the refunds are showing on the invoice?

    Thread Starter omnisity

    (@omnisity)

    Hi Muhammad,

    Thanks for the beta version, I’ve been able to run a manual and scheduled scan which were both ran sucessful.

    Thread Starter omnisity

    (@omnisity)

    ` wp-core
    
    version: 6.3.1
    site_language: en_GB
    user_language: en_GB
    timezone: Europe/London
    permalink: /%postname%/
    https_status: true
    multisite: false
    user_registration: 0
    blog_public: 1
    default_comment_status: undefined
    environment_type: production
    user_count: 168
    dotorg_communication: true wp-paths-sizes
    
    
    name: OmniScaffold Child Theme (bb-theme-child)
    version: 1.0.1
    author: Omnisity Development Team
    author_website: http://www.omnisity.com
    parent_theme: Beaver Builder Theme (bb-theme)
    theme_features: core-block-patterns, woocommerce, widgets-block-editor, post-thumbnails, fl-theme-builder-headers, fl-theme-builder-footers, fl-theme-builder-parts, automatic-feed-links, title-tag, align-wide, wp-block-styles, html5, menus, wc-product-gallery-zoom, wc-product-gallery-lightbox, wc-product-gallery-slider, widgets
    
    name: Beaver Builder Theme (bb-theme)
    version: 1.7.14
    author: The Beaver Builder Team
    author_website: http://www.wpbeaverbuilder.com/?utm_medium=bb-pro&utm_source=bb-theme&utm_campaign=themes-admin-page
    auto_update: Disabled wp-themes-inactive (1)
    
    Twenty Twenty-Three: version: 1.2, author: the WordPress team, Auto-updates disabled wp-mu-plugins (2)
    
    ManageWP - Worker Loader: version: 1.0.0, author: GoDaddy
    Object Cache Pro (MU): version: 1.20.0, author: Rhubarb Group wp-plugins-active (47)
    
    Admin Menu Editor Pro: version: 2.21.1, author: Janis Elsts, Auto-updates disabled
    Advanced Custom Fields PRO: version: 6.2.1.1, author: WP Engine, Auto-updates disabled
    AME Branding Add-on: version: 1.3.6, author: Janis Elsts, Auto-updates disabled
    Beaver Builder Plugin (Agency Version): version: 2.7.2.2, author: The Beaver Builder Team, Auto-updates disabled
    Beaver Builder Sticky Column: version: 1.5.4, author: Sitespot Dev, Auto-updates disabled
    Beaver Team Z-Index Add On for Beaver Builder: version: 1.0.1, author: SiteSpot Dev, Auto-updates disabled
    Beaver Themer: version: 1.4.8, author: The Beaver Builder Team, Auto-updates disabled
    Change wp-admin login: version: 1.1.7, author: wpexpertsio, Auto-updates disabled
    Classic Editor: version: 1.6.3, author: WordPress Contributors, Auto-updates disabled
    Classic Widgets: version: 0.3, author: WordPress Contributors, Auto-updates disabled
    Contact Form 7: version: 5.8.1, author: Takayuki Miyoshi, Auto-updates disabled
    CookieYes | GDPR Cookie Consent: version: 3.1.4, author: CookieYes, Auto-updates disabled
    Custom Product Tabs for WooCommerce: version: 1.8.5, author: Code Parrots, Auto-updates disabled
    Equal Height Columns: version: 1.1.4, author: MIGHTYminnow, Mickey Kay, Braad Martin, Auto-updates disabled
    FiboSearch - AJAX Search for WooCommerce: version: 1.25.0, author: FiboSearch Team, Auto-updates disabled
    GTM4WP: version: 1.18.1, author: Thomas Geiger, Auto-updates disabled
    ManageWP - Worker: version: 4.9.17, author: GoDaddy, Auto-updates disabled
    Max Mega Menu: version: 3.2.3, author: megamenu.com, Auto-updates disabled
    Max Mega Menu - Pro Addon: version: 2.2.9.1, author: megamenu.com, Auto-updates disabled
    NP Quote Request WooCommerce: version: 1.9.109, author: Neah Plugins, Auto-updates disabled
    NP Quote Request WooCommerce Plus: version: 1.7.51, author: Neah Plugins (latest version: 1.7.52), Auto-updates disabled
    Omnisity Addons: version: 2.0.5, author: Omnisity, Auto-updates disabled
    Omnisity Contact: version: 4.0.3, author: Omnisity, Auto-updates disabled
    PDF Thumbnails Premium: version: 1.4.2, author: Dan Lester, Auto-updates disabled
    Post SMTP: version: 2.6.1, author: Post SMTP, Auto-updates disabled
    PowerPack for Beaver Builder: version: 2.33.2, author: IdeaBox Creations, Auto-updates disabled
    Rank Math SEO: version: 1.0.203, author: Rank Math, Auto-updates disabled
    Rank Math SEO PRO: version: 3.0.46, author: Rank Math, Auto-updates disabled
    Redirection for Contact Form 7: version: 3.0.1, author: Qube One, Auto-updates disabled
    Remove Dashboard Access: version: 1.1.5, author: TrustedLogin, Auto-updates disabled
    Revolut Gateway for WooCommerce: version: 4.9.1, author: Revolut, Auto-updates disabled
    Simple Page Ordering: version: 2.5.1, author: 10up, Auto-updates disabled
    Stream: version: 3.9.3, author: XWP, Auto-updates disabled
    Timed Content for Beaver Builder: version: 1.0.3, author: Pratik Chaskar, Auto-updates disabled
    Title and Nofollow For Links: version: 1.12, author: WPKube, Auto-updates disabled
    Ultimate Addons for Beaver Builder: version: 1.35.15, author: Brainstorm Force, Auto-updates disabled
    UpdraftPlus - Backup/Restore: version: 1.23.10, author: UpdraftPlus.Com, DavidAnderson, Auto-updates disabled
    WooCommerce: version: 8.1.1, author: Automattic, Auto-updates disabled
    WooCommerce Opayo Payment Suite: version: 5.10.3, author: Andrew Benbow, Auto-updates disabled
    WooCommerce PayPal Payments: version: 2.3.1, author: WooCommerce, Auto-updates disabled
    Wordfence Security: version: 7.10.4, author: Wordfence, Auto-updates disabled
    WordPress Toolbar Editor: version: 1.4.2, author: Janis Elsts, Auto-updates disabled
    WP File Manager: version: 7.2, author: mndpsingh287, Auto-updates disabled
    WP Media folder: version: 5.6.3, author: Joomunited, Auto-updates disabled
    WP Rocket: version: 3.15.1, author: WP Media, Auto-updates disabled
    WP Rocket | Redirect HTTP to HTTPS: author: WP Rocket Support Team, version: (undefined), Auto-updates disabled
    WP Rocket | Redirect non-www to www: author: WP Rocket Support Team, version: (undefined), Auto-updates disabled wp-plugins-inactive (1)
    
    Imagify: version: 2.1.2, author: Imagify – Optimize Images & Convert WebP, Auto-updates disabled wp-media
    
    image_editor: WP_Image_Editor_Imagick
    imagick_module_version: 1690
    imagemagick_version: ImageMagick 6.9.10-23 Q16 x86_64 20190101 https://imagemagick.org
    imagick_version: 3.7.0
    file_uploads: File uploads is turned off
    post_max_size: 100M
    upload_max_filesize: 100M
    max_effective_size: 100 MB
    max_file_uploads: 20
    imagick_limits:
    imagick::RESOURCETYPE_AREA: 31 GB
    imagick::RESOURCETYPE_DISK: 1.844674407371E+19
    imagick::RESOURCETYPE_FILE: 768
    imagick::RESOURCETYPE_MAP: 31 GB
    imagick::RESOURCETYPE_MEMORY: 16 GB
    imagick::RESOURCETYPE_THREAD: 1
    imagick::RESOURCETYPE_TIME: 1.844674407371E+19
    imagemagick_file_formats: 3FR, 3G2, 3GP, AAI, AI, ART, ARW, AVI, AVS, BGR, BGRA, BGRO, BIE, BMP, BMP2, BMP3, BRF, CAL, CALS, CANVAS, CAPTION, CIN, CIP, CLIP, CMYK, CMYKA, CR2, CRW, CUR, CUT, DATA, DCM, DCR, DCX, DDS, DFONT, DJVU, DNG, DOT, DPX, DXT1, DXT5, EPDF, EPI, EPS, EPS2, EPS3, EPSF, EPSI, EPT, EPT2, EPT3, ERF, EXR, FAX, FILE, FITS, FRACTAL, FTP, FTS, G3, G4, GIF, GIF87, GRADIENT, GRAY, GRAYA, GROUP4, GV, H, HALD, HDR, HEIC, HISTOGRAM, HRZ, HTM, HTML, HTTP, HTTPS, ICB, ICO, ICON, IIQ, INFO, INLINE, IPL, ISOBRL, ISOBRL6, J2C, J2K, JBG, JBIG, JNG, JNX, JP2, JPC, JPE, JPEG, JPG, JPM, JPS, JPT, JSON, K25, KDC, LABEL, M2V, M4V, MAC, MAGICK, MAP, MASK, MAT, MATTE, MEF, MIFF, MKV, MNG, MONO, MOV, MP4, MPC, MPEG, MPG, MRW, MSL, MSVG, MTV, MVG, NEF, NRW, NULL, ORF, OTB, OTF, PAL, PALM, PAM, PANGO, PATTERN, PBM, PCD, PCDS, PCL, PCT, PCX, PDB, PDF, PDFA, PEF, PES, PFA, PFB, PFM, PGM, PGX, PICON, PICT, PIX, PJPEG, PLASMA, PNG, PNG00, PNG24, PNG32, PNG48, PNG64, PNG8, PNM, PPM, PREVIEW, PS, PS2, PS3, PSB, PSD, PTIF, PWP, RADIAL-GRADIENT, RAF, RAS, RAW, RGB, RGBA, RGBO, RGF, RLA, RLE, RMF, RW2, SCR, SCT, SFW, SGI, SHTML, SIX, SIXEL, SPARSE-COLOR, SR2, SRF, STEGANO, SUN, SVG, SVGZ, TEXT, TGA, THUMBNAIL, TIFF, TIFF64, TILE, TIM, TTC, TTF, TXT, UBRL, UBRL6, UIL, UYVY, VDA, VICAR, VID, VIFF, VIPS, VST, WBMP, WEBP, WMF, WMV, WMZ, WPG, X, X3F, XBM, XC, XCF, XPM, XPS, XV, XWD, YCbCr, YCbCrA, YUV
    gd_version: 2.3.3
    gd_formats: GIF, JPEG, PNG, WebP, BMP, XPM
    ghostscript_version: unknown wp-server
    
    server_architecture: Linux 6.2.9-x86_64-linode160 x86_64
    httpd_software: Apache/2.4.57 (Debian)
    php_version: 7.4.33 64bit
    php_sapi: fpm-fcgi
    max_input_variables: 10000
    time_limit: 300
    memory_limit: 256M
    max_input_time: 60
    upload_max_filesize: 100M
    php_post_max_size: 100M
    curl_version: 7.64.0 OpenSSL/1.1.1n
    suhosin: false
    imagick_availability: true
    pretty_permalinks: true
    htaccess_extra_rules: true
    current: 2023-10-09T10:08:56+00:00
    utc-time: Monday, 09-Oct-23 10:08:56 UTC
    server-time: 2023-10-09T11:08:54+01:00 wp-database
    
    extension: mysqli
    server_version: 10.4.20-MariaDB-1:10.4.20+maria~buster-log
    client_version: mysqlnd 7.4.33
    max_allowed_packet: 134217728
    max_connections: 29538 wp-constants
    
    WP_MEMORY_LIMIT: 40M
    WP_MAX_MEMORY_LIMIT: 256M
    WP_DEBUG: false
    WP_DEBUG_DISPLAY: true
    WP_DEBUG_LOG: false
    SCRIPT_DEBUG: false
    WP_CACHE: true
    CONCATENATE_SCRIPTS: undefined
    COMPRESS_SCRIPTS: undefined
    COMPRESS_CSS: undefined
    WP_ENVIRONMENT_TYPE: Undefined
    WP_DEVELOPMENT_MODE: undefined
    DB_CHARSET: utf8
    DB_COLLATE: undefined wp-filesystem
    
    wordpress: writable
    wp-content: writable
    uploads: writable
    plugins: writable
    themes: writable
    mu-plugins: writable objectcache
    
    general-status: Connected
    general-dropin: Valid
    general-license: Valid
    general-env: production
    general-multisite: No
    general-mu: Yes
    general-vcs: No
    general-host: cloudways
    general-eviction-policy: allkeys-lfu
    general-compressions: LZF, LZ4, ZSTD
    general-basename: redis-cache-pro.php
    general-client: RedisCachePro\Clients\PhpRedis
    versions-php: 7.4.33 (Outdated)
    versions-igbinary: 3.2.14
    versions-phpredis: 6.0.0
    versions-relay: Not installed
    versions-redis: 7.2.1
    versions-plugin: 1.20.0
    versions-dropin: 1.20.0
    statistics-redis-memory: 50 MB of 793 MB
    statistics-redis-keys: 17675
    groups-global: [
    "analytics",
    "objectcache",
    "blog-details",
    "blog-id-cache",
    "blog-lookup",
    "blog_meta",
    "global-posts",
    "networks",
    "network-queries",
    "sites",
    "site-details",
    "site-options",
    "site-queries",
    "site-transient",
    "rss",
    "users",
    "user-queries",
    "user_meta",
    "useremail",
    "userlogins",
    "userslugs"
    ]
    groups-non-persistent: [
    "counts",
    "plugins",
    "theme_json",
    "themes",
    "wordfence",
    "wordfence-ls"
    ]
    groups-non-prefetchable: [
    "analytics",
    "objectcache",
    "userlogins",
    "wc_session_id"
    ]
    config-token: ••••••••001c
    config-connector: RedisCachePro\Connectors\PhpRedisConnector
    config-cache: RedisCachePro\ObjectCaches\PhpRedisObjectCache
    config-logger: RedisCachePro\Loggers\ErrorLogLogger
    config-log_levels: emergency, alert, critical, error, warning
    config-scheme: tcp
    config-host: 127.0.0.1
    config-port: 6379
    config-database: 3493
    config-username: null
    config-password: null
    config-prefix: jaqegnuykm
    config-maxttl: null
    config-timeout: 2.5s
    config-read_timeout: 2.5s
    config-retry_interval: 25ms
    config-retries: 3
    config-backoff: smart
    config-persistent: false
    config-shared: null
    config-async_flush: true
    config-group_flush: keys
    config-network_flush: all
    config-cluster: null
    config-cluster_failover: error
    config-servers: null
    config-replication_strategy: distribute
    config-sentinels: null
    config-service: null
    config-tracer: none
    config-serializer: igbinary
    config-compression: zstd
    config-global_groups: null
    config-non_persistent_groups: null
    config-non_prefetchable_groups: null
    config-prefetch: true
    config-split_alloptions: true
    config-analytics: {
    "enabled": true,
    "persist": true,
    "retention": 7200,
    "sample_rate": 100,
    "footnote": true
    }
    config-relay: {
    "cache": true,
    "listeners": false,
    "invalidations": true,
    "allowed": null,
    "ignored": [
    ":analytics:"
    ]
    }
    config-tls_options: null
    config-updates: true
    config-debug: false
    config-strict: false
    config-save_commands: false
    environment-WP_REDIS_DISABLED: 0
    environment-OBJECTCACHE_CONFIG: undefined
    constants-WP_DEBUG: false
    constants-SAVEQUERIES: undefined
    constants-WP_REDIS_DIR: undefined
    constants-WP_REDIS_DISABLED: false
    constants-WP_REDIS_CONFIG: {
    "token": "••••••••001c",
    "host": "127.0.0.1",
    "port": 6379,
    "database": "3493",
    "timeout": 2.5,
    "read_timeout": 2.5,
    "split_alloptions": true,
    "async_flush": true,
    "client": "phpredis",
    "compression": "zstd",
    "serializer": "igbinary",
    "prefetch": true,
    "debug": false,
    "save_commands": false,
    "prefix": "jaqegnuykm"
    }
    Thread Starter omnisity

    (@omnisity)

    Hi,

    You can find an error log on this thread:

    • [Aug 23 07:31:20] Scan Engine Error: The signature on the request to start a scan is invalid. Please try again.
    • [Aug 23 07:32:37] Attempting to resume scan stage (1 attempt(s) remaining)…
    • [Aug 23 07:32:40] Scan Engine Error: The signature on the request to start a scan is invalid. Please try again.
    • [Aug 23 07:34:31] Attempting to resume scan stage (0 attempt(s) remaining)…
    • [Aug 23 07:34:34] Scan Engine Error: The signature on the request to start a scan is invalid. Please try again.
    • [Aug 23 10:33:46] Scan stop request received.
    • [Aug 23 10:33:47] Scan stop request received.
    • [Aug 23 10:33:57] Scan Engine Error: The signature on the request to start a scan is invalid. Please try again.
    • [Aug 23 10:35:51] Attempting to resume scan stage (1 attempt(s) remaining)…
    • [Aug 23 10:35:54] Scan Engine Error: The signature on the request to start a scan is invalid. Please try again.
    • [Aug 23 10:37:20] Attempting to resume scan stage (0 attempt(s) remaining)…
    • [Aug 23 10:37:22] Scan Engine Error: The signature on the request to start a scan is invalid. Please try again.

    @wfphil suggested disabling the plugin, which did enable a manual scan, but we’re unable to auto scan with the plugin enabled:

    https://ww.wp.xz.cn/support/topic/scan-engine-error-the-signature-on-the-request-to-start-a-scan-is-invalid-2/

    Hi Phil,

    Thanks for getting back to me, i can confirm disabling the plugin has enabled scanning for two sites (checked so far), I’ll check the rest i’m having issues with and report back should they not have this plugin installed.. Safe to assume it’s a conflict with this plugin then?

    Looking at log, it’s only started happening from around August 10th which may correspond to the last update, is it worth me opening a support ticket with them?

    We like to change the Admin login page, as another security measure, so it is functionality we’d like to keep if possible.

    I’m also expiriencing this issue across a number of site’s I manage, I’ve sent diagnostic reports, but haven’t recieved any reply. Does anyone have expirience of the standard response times with the FREE licences?

    I've been trying to find a resolution for this for months against on a number of sites I manage. I typically run the latest plugin version available, so I'm not sure if this will work on older systems. But if like me your WooCommerce status widget was missing and was replaced by the "finish setup" widget, this may help you. As advised above you can restart the setup process and click skip at each stage. However, with my builds I was unable to skip the "get more sales" step, which meant my builds were never complete. Having tried to install Google Ads / mail chimp, it still didn't restore the status widget and caused errors logs, because accounts weren't setup. 
    
    Having explored plugin conflicts and after extensive trial and error, I stumbled across a solution which I found in the WooCommerce documentation (but I can't seem to find the link as of writing this thread). The following process has worked on all sites for me, so give it a go. 
    
    Go to any WooCommerce Settings page e.g.
    
    https://[domain].com/wp-admin/admin.php?page=wc-settings
    
    Click Help tab (top right) > Click Setup wizard
    
    Under Task list click the disable (blue button)
    
    Return to the dashboard, if the Status widget is still not available, click screen options and make sure the WooCommerce Status checkbox is ticked and it should be back!
    
    Hope this helps someone out!
    Thread Starter omnisity

    (@omnisity)

    Hi Mikkel,

    Thanks for your response, however we have now implemented the fix suggested above.

    Thread Starter omnisity

    (@omnisity)

    Excellent, thank you.

Viewing 12 replies - 1 through 12 (of 12 total)