• marceloesr

    (@marceloesr)


    Dear fellows

    After the last update v1.3, the Visual Footer Credit Remover stop to work. Even showing the correct substitution on Visual Editor, it’s not working when loading the site, when the orginal Blossom footer is shown.

    I have tried replace, insert, before or after, all of them do nothing.

    The chosen selector is FOOTER[id=’colophon’] > DIV, but even using FOOTER[id=’colophon’] > DIV > DIV is not working.

    Any tips?

    The page I need help with: [log in to see the link]

Viewing 4 replies - 1 through 4 (of 4 total)
  • Malae

    (@malae)

    @marceloesr
    I have the same problem. There appears to be a syntax error in the last update (see previous posting). I suggest that you can roll back to the previous version until the problem is fixed.

    Thread Starter marceloesr

    (@marceloesr)

    I did that, thank you

    Malae

    (@malae)

    @marceloesr

    I discovered that the recent update that didn’t work was made because of a security vulnerability.
    Visual Footer Credit Remover <= 1.2 – Authenticated (Admin+) Stored Cross-Site Scripting
    Patched CVE-2024-2846
    So we should consider that rolling back to version 1.2 will expose the site to this vulnerability.

    @marceloesr

    Further information on the vulnerability:
    The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘selector’ parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Viewing 4 replies - 1 through 4 (of 4 total)
  • You must be logged in to reply to this topic.