  • #1407860

    Enfold (5.6.2)

    Please update 3rd party component.

    jszip 3.6.0 Found in wp-content/themes/enfold/config-lottie-animations/assets/lottie-player/dotlottie-player.js?ver=5.6.2 _____Vulnerability info:
    High Santize filenames when files are loaded with loadAsync, to avoid “zip slip” attacks. 5 CVE-2022-48285 GHSA-36fh-84j7-cv5h 1
    Medium Prototype Pollution CVE-2021-23413 GHSA-jg8v-48h5-wgxg

    thank you!


    Hey testq1,

    Thank you for reporting this.

    I updated the component for next release.

    Best regards,


    is it possible that this did not happen?
    It seems hat 3.6 is still in the code instead of 3.10 or am I wrong?
    Best, Tom


    Hi skopos-connect,

    Which version of the theme are you running?

    Best regards,


    Hi Rikard,
    we are running Version 6.0.4 currently. It seems that there is 6.0.6 out now.
    As it is hard to find out, what version is used, we found these comments inside dotlottie-player.js

    JSZip v3.6.0 – A JavaScript class for generating and reading zip files

    (c) 2009-2016 Stuart Knightley <stuart [at]>
    Dual licenced under the MIT license or GPLv3. See

    JSZip uses the library pako released under the MIT license :
    JSZip v3.5.0 – A JavaScript class for generating and reading zip files

    (c) 2009-2016 Stuart Knightley <stuart [at]>
    Dual licenced under the MIT license or GPLv3. See

    JSZip uses the library pako released under the MIT license :

    Best Regards



    We tried, but could not update the js file to a later version – it had seemed to be buggy and using the methods to control the animation like play, pause, .. did not work as it should. So we left it unchanged.

    Checking the player today ( the implementation has completly changed.

    We will add it to our dev repo to consider updateing the element – but we have no ETA for it yet.

    Best regards,

