Visual Composer Security Issue (Updates)

Posted in: Newspaper
Post count: 88

Hello,

As you’re providing the Visual composer plugin for free with every purchase. If you can, then you should try enabling the automatic updates of Visual composer plugins for your user. For what? For security reasons… If there’s a new plugin version, that means there may be a security vulnerability in the previous version (may be a serious thing or a least thing of concern).

However, you provide new plugin updates along with a new version of Newspaper. You try to give it as soon as possible. I understand. But, “Security Breaches” don’t really wait for “as soon as possible”. Hope you understand my security concern. And, I don’t want anyone’s site getting compromised because of the outdated Visual Composer plugin.

Post count: 23312

Hello ankush,

Unfortunately, we cannot release the automatic update for Visual Composer because each new version of Visual Composer is still necessary to check deeper before launching this. If we will do as you say above, it would be more likely that the theme will not work as properly and probably you will request our help to fix that. Please keep in mind that we want to avoid these cases and we want that our theme to work as expected. I hope that you understand my message. If you disagree with this schedule, you can buy the Visual Composer plugin and all the issues that appear in our theme you will have to contact the Visual Composer support.

Thank you!

Post count: 88

Well, yes I certainly understand that! Thanks for the explanation.
However, it would be awesome if you could speed up the process to prevent quick security breaches on websites.
Compatibility is definitely important and that’s why you need time to test it. But, security is important as well. I hope this thing improves in the future 🙂

Cheers!

Post count: 9544

VC Changelog:
https://wpbakery.atlassian.net/wiki/display/VC/Release+Notes

What current vulnerability in VC 4.11 are you so worried about exactly that you need 4.11.1 “right now.”

Last time there was major security flaw announced in VC, TagDiv had update to theme and VC same day the patch was released. So not big worry there. 100,000 users are a priority for TagDiv, so they don’t wait a month to patch things based on being around here myself the past 2.5 years.

Just some feedback 🙂
( I don’t work here . . . )

Viewing 4 posts - 1 through 4 (of 4 total)
You must be logged in to reply to this topic.