-
Notifications
You must be signed in to change notification settings - Fork 34
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerabilities has discovered - SQL Injection #57
Comments
@rajankarmakar thanks for the feedback. Personaly, I think there is some exaggeration here. Of course it is possible to change things, but for this an administrative access is needed and if this is in the possession of someone else, the plugin itself is not the problem! @hijiriworld have you found the time to take a deeper look into the PR54. Would love to fix the security issues and use this PR as starting point. |
@timohubois Can you say anything about the timing of the fix or if it will be fixed by the next release? |
Would really love to fix it and currently I’m waiting for feedback from @hijiriworld, to get a better starting point. |
#54 is merged. Will start to work on this asap. |
Created a branch with some changes: https://github.com/hijiriworld/intuitive-custom-post-order/pull/ |
Vulnerabilities have discovered that the currently installed version of the Intuitive Custom Post Order plugin has known security vulnerabilities. See more.
The text was updated successfully, but these errors were encountered: