xwp / stream

🗄️ Stream plugin for WordPress
https://wordpress.org/plugins/stream/
GNU General Public License v2.0
407 stars 116 forks source link

Vulnerability in 3.9.2 #1426

Closed alexincore closed 1 year ago

alexincore commented 1 year ago

Feature Request / Question

Patchstack reported version 3.9.2 as being vulnerable to CSRF https://patchstack.com/database/vulnerability/stream/wordpress-stream-plugin-3-9-2-cross-site-request-forgery-csrf-vulnerability?_a_id=431

Any chance you have it in your queue?

kasparsd commented 1 year ago

Thanks for reporting this! We received the first report of the issue only a few hours ago and are looking into this.

Japh commented 1 year ago

Do we know when this fix will be released onto the WP.org plugin repo? Thanks for fixing it!

mustafauysal commented 1 year ago

It appears to be available on .org now! Thanks for the fix! 👍🏼

alexincore commented 1 year ago

Thank you!