Cross site scripting vulnerability not addressed?

Posted in: Newsmag
Post count: 4

Hi guys Im just getting going with this but am concerned to see WordPress flagging a High security risk with no apparent ip to date mitigation.
Your guidance much appreciated.

Kind regards
David

WordPress NewsMag theme <= 2.4.4 – Reflected Cross-Site Scripting (XSS) vulnerability
Reflected Cross-Site Scripting (XSS) vulnerability discovered by Brandon Roldan in WordPress Theme Newsmag (versions <= 2.4.4)
Date: 16.03.2023 | Source: PatchstackWordfence

Post count: 20688

Hi,

Are you sure that’s our Newsmag theme? Because ours didn’t have a 2.4.4 version. Maybe it refers to this theme https://patchstack.com/database/wordpress/theme/newsmag which appears to have been abandoned a few years ago at version 2.4.4 https://themes.trac.wordpress.org/log/newsmag/ Certainly looks that way.

Our latest theme version is 5.4.3.3 and we have patched every known vulnerability https://tagdiv.com/newsmag/

Thanks

Post count: 4

Hi Simion
Thank you for getting back to me.
If Im reading this correctly the warning is saying a vulnerability was identified up to and including version 2.4.4. So if we’re now on 5.4.3.3 why are they making life difficult? Presumably I can just ignore this and you’re correct that they are talking about an out of date version.
Apologies for the confusion

Post count: 20688

Not sure exactly. Maybe its truly a case of different themes, both being called Newsmag. That other theme called Newsmag stopped at version 2.4.4. Our theme is nowhere near that version, and our theme didn’t have a 2.4.4 version, the changelog is available here at the bottom https://themeforest.net/item/newsmag-news-magazine-newspaper/9512331 So it’s safe to say that the notification you mentioned is no reason to worry.

Thanks.

Viewing 4 posts - 1 through 4 (of 4 total)
The forum ‘Newsmag’ is closed to new topics and replies.