Security issue – will it be fixed??
-
Will you be issuing a fix for this vulnerability?
Constant Contact Forms plugin <= 1.14.0 – Broken Access Control vulnerability
-
This topic was modified 2 years, 8 months ago by
caordawebsol.
-
This topic was modified 2 years, 8 months ago by
-
Can you provide where you’re seeing this report, or what tool you’re using to see this, so that we can get more information about reported issues and check on if our next release is going to already cover it or not?
Any extra information would be greatly appreciated.
Thanks for the link, we’ll be reviewing it as soon as possible.
Checking in on this as well. Any ETA for an update that is not vulnerable?
Or, do you have another preferred solution that replaces this?
Thanks.
We put the security related fix, pointed out with better detail for where from a review received this morning, in as part of the 2.0.0 major release that we pushed up to wordpress.org this afternoon.
Thank you!
When reconnecting using the code provided once logged into CC, the site throws a 500 error:
An error of type E_ERROR was caused in line 754 of the file XXX/wp-content/plugins/constant-contact-forms/includes/class-lists.php. Error message: Uncaught Error: Cannot use object of type Ctct\Components\Contacts\ContactList as array in XXX/wp-content/plugins/constant-contact-forms/includes/class-lists.php:754Hi @caordawebsol we are checking on that right now. Thank you for the information
You can download version 2.0.1 via https://downloads.wordpress.org/plugin/constant-contact-forms.2.0.1.zip and since you’re experiencing fatal errors, it’ll probably have to be a manual upload.
Our apologies about that necessary step, it was definitely not our intention.
Thanks for addressing it so quickly – trying now.
Working great now – thanks so much!
Side note – show_title=false doesn’t seem to be working any more….
[ctct form=”177″ show_title=”false”]
@caordawebsol Not managing to recreate that issue with the title. Can you attempt saving the page where the shortcode is at and see if that somehow clears up the issue?
I’m now having issues syncing lists – once new code is copied over, it doesn’t “see” the lists. Screen shows zero lists, even after clicking sync
-
This reply was modified 2 years, 8 months ago by
caordawebsol.
Can you visit Settings > Support tab and enable the debugging setting? I’m curious if there’s already some logs in place in the debug log menu item that will show. If not, enable the debugging and re-try syncing the lists. Hopefully then something will show in the logs that we can use to troubleshoot.
-
This reply was modified 2 years, 8 months ago by
The topic ‘Security issue – will it be fixed??’ is closed to new replies.