Vulnerability to Remote Code Execution (RCE)
We had a site hacked today and in order to remediate it, they want us to have an answer to this Remote Code Excecution.
The link is for 28.4.2 But I've updated the site to run 28.5.6
[Links visible only for registered users]
Can you tell me if the RCE was addresses in 28.5.6?
Comments
They are also complaining about Slider Rev. Can that be updated? I know betheme is usually a version or two behind on that.
Hi,
this have been fixed many months ago. We've informed Wordfence few times regarding this "vulnerability" but so far we didn't get any response. Please note it's beyond our control what they do and what they actually advertise as vulnerability is false positive.
According to Slider Revolution, there is latest version bundled with Betheme according to changelog [Links visible only for registered users]
Thanks. It was patchstack that was complaining. Wordfence didn't complain.
They're being unreasonable about Slider Rev. It's appears up to date to me. But they're saying "To update the plugin, you'll need to reach out to the plugin author or developer to obtain or renew an active license. Once the license is activated, you should be able to access the latest available updates."
I have to remove the slider completely to get them to remediate the site. Just a hassle!
Patchstack gets information about vulnerabilities from Wordfence hence you got this false positive notice.
Regarding SR, are you talking about SR7? If yes, it's completely new product that is not going to be bundled because plugin's author decided to support SR6 only for those who have bundled version. Plugin's author simply decided not to provide version 7 as version that could be bundled with the theme but it has absolutely nothing to do with us. Further details regarding this, you will find on [Links visible only for registered users]