Home User profile
tagDiv Member
This user did not write anything. So we are just showing here some random text to make the profile page look nice :)
shanean1
tagDiv Member

WPScan references Wordfence.
Wordfence says 3.9 is bad, 4.0 is fixed, references Patchstack.
Patchstack says 3.9.1 is bad, 3.9.2 is the fixed version.

Same CVE.

One of them is right!

shanean1
tagDiv Member

Annnnd I found it again, aaaaand it was object caching.

Please ignore again!

shanean1
tagDiv Member

Yeah,

Strangely 3 months later, I have this issue back again.

Any ideas on what could be the cause? I believe I am storing variables in object cache, so it shouldn’t need to ping for every single wp_admin request…

shanean1
tagDiv Member

Answer found:

If you run W3 Total Cache with an object cache, remove “plugins” from the list of “Non-persistent groups” in the object cache settings.

shanean1
tagDiv Member

I think what happened here is the vulnerability monitors have seen the message saying vulnerable in versions < 2.7 and concluded that 2.7 was vulnerable.

Without knowing the details of the exploit, I notice the person who found the issue reports that Newspaper 12.4 is not vulnerable, which came with TagDiv Cloud Library 2.7, so I believe that 2.7 is definitely OK, and it’s just a false alert.

WPScan reports it is as vulnerable on < 2.7 and fixed on 2.7: https://wpscan.com/vulnerability/4eafe111-8874-4560-83ff-394abe7a803b

Viewing 5 posts - 1 through 5 (of 5 total)