Webman Amplifier Security Vulnerability

Home Forums Legacy themes & others Webman Amplifier Security Vulnerability

robwas66
Participant
#33477
Resolved

Support, my latest Wordfence security scan came up with a security vulnerability for the Webman Amplifier plugin.

“The Plugin “WebMan Amplifier” has a security vulnerability.”
More Info:
The WebMan Amplifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.12 due to insufficient input sanitization and output escaping.
This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Any chance of a plugin update/patch to fix this?

Best!
– RObert

  • This topic was modified 1 month ago by Oliver Juhas. Reason: Formatting text
  • This topic was modified 1 month ago by Oliver Juhas. Reason: Plugin related question, moving to "Others" forum
Viewing 3 replies – 1 through 3 (of 3 total)
WebMan Design
Keymaster
#33478

Hi RObert,

Thank you for reporting this.

I’m not aware of any vulnerability in the plugin, and it was actually coded with security in mind. But I will certainly go through the plugin’s code and tighten some bolts wherever needed and will release the plugin update soon.

However, please understand that I can’t really say whether Wordfence stops reporting the issue afterwards.

Best regards,

Oliver Juhas
WebMan Design

WebMan Design
Keymaster
#33481

BTW, from the description of the issue, it seems it happens only in admin interface. This means, if you don’t allow user registration on your website, you should be safe even currently.

Best regards,

Oliver Juhas
WebMan Design

WebMan Design
Keymaster
#33523

Hi robwas66,

I’ve just released WebMan Amplifier 1.6.0 update. This is a significant plugin update with improved security. If you find any issue, please report it here. Thank you.

Best regards,

Oliver Juhas
WebMan Design

Viewing 3 replies – 1 through 3 (of 3 total)

You must be logged in to reply to this ticket.