ThemeFuse / Unyson

A WordPress framework that facilitates the development of WP themes
http://unyson.io
923 stars 219 forks source link

Access violation vulnerability #4331

Open roozbehzarei opened 9 months ago

roozbehzarei commented 9 months ago

The Unyson plugin for WordPress is vulnerable to unauthorized access and modification of data. This means that people who have a subscriber-level access or higher may be able to do things that they are not allowed to do, like dismiss notices. This vulnerability exists in all versions of Unyson up until version 2.7.28.

Source: Really Simple SSL

twright6 commented 9 months ago

Tie this issue to 4330 labeled Patch. Same issue!

DevMasterAGI commented 8 months ago

If anyone wishes to voice their concerns, the email address We have been using is: support@brizy.io for Unyson issue. Please email there support.

roozbehzarei commented 8 months ago

We need to start review bombing ThemeFuse products on ThemeForest to force devs release updates, or lose their income otherwise.

charlycoder commented 6 months ago

If anyone wishes to voice their concerns, the email address We have been using is: support@brizy.io for Unyson issue. Please email there support.

they send it: Hi Carlos,

we are doing our best to answer your ticket (32572) ASAP. Usually it takes 24 hours to get the problem solved, but if there is a bug that may require coding, it may take up to 3 days or more.

To help us to solve your issue faster, will be great if you can provide your WordPress installation link, username and password from your WordPress dashboard, as well FTP details, in case you get some errors or plugin appears broken.

(This is an automatic message, if you’ve included your WP login credentials when you submitted your ticket, or if this doesn’t apply to you, please disregard this message.)

To add additional comments, reply to this email.

I find it very strange that they ask for username and password to login to my wordpress, this should be treated with care.