prettyPhoto XSS

Posted in: Newsmag
Post count: 90

Hi, visual composer had a XSS security problem related to prettyPhoto, it has been fixed with 4.3.5. When/where is it used with this theme?

I’ve newsmag 1.7.1 with VC 4.2.2, am I safe (from prettyPhoto and other vulerabilities)? I would like to avoid upgrades for the moment if they’re not necessary for security reasons.

thanks for your incredible work.

  • This topic was modified 11 years by daimpa.
Post count: 6600

Hi,

Seems that the prettyPhoto security issue was aborted in 4.5.3 update according to their update logs: http://screencast.com/t/WaCN5Zle72ow

The latest theme version (2.0) now available on themeforest has the 4.5.3 version of the VC plugin included so it’s safe for you to download it, update the theme then update the plugin if you want: https://forum.tagdiv.com/how-to-update-theme/https://forum.tagdiv.com/how-to-update-visual-composer-plugin-wpbakery/

Thanks for the message!

Viewing 2 posts - 1 through 2 (of 2 total)
You must be logged in to reply to this topic.