Cross-Site Scripting (XSS) Vulnerability in NewsPaper

Posted in: Newspaper
Post count: 1

Hi Newspaper Team,

Wpvulndb reported that there is a security vulnerability in v <= v9.2.2 (https://wpvulndb.com/vulnerabilities/9218) and it is fixed in v9.5

We are currently using Newspaper v7.8. But it is not possible to directly upgrade to v9.5 from v7.8 since we needs additional testing times and had some code modification on core templates files.

Can you please provide which part of the code is vulnerable and the hot fix code to fix it? We only want to fix the only vulnerability part instead of the whole theme major upgrade.

Thanks.

  • This topic was modified 7 years by sphddss.
Post count: 35449

Hi,

Please not that all fix that was implemented in our theme was tested only in version that those fix appear and greater, this will not work in previous versions, sorry; the only way to have those fix in theme is to make the update, you can make it on localhost and until you get all modification set from v7.8 to v9.5
Sorry for the inconvenience!

Thank you for your understanding!

Post count: 1

we have been on 9.2.2 for over a year and are dealing with this issue now. we plan to upgrade to 10.3.2 next week but need to stage site first.

is there a way to quickly update to 9.5 to rid the XSS vulnerability ASAP planning to upgrade fully in a few days?

Post count: 35449

Hi,

All possibilities to update the theme can be found here:
-> https://forum.tagdiv.com/how-to-update-the-theme-2/
And yes first it will be recommended to make the update on test environment to make sure that everything is working correctly.

Thank you!

Viewing 4 posts - 1 through 4 (of 4 total)
The forum ‘Newspaper’ is closed to new topics and replies.