Tagged: 

Viewing 13 posts - 1 through 13 (of 13 total)
  • Author
    Posts
  • #1494213

    Is a update 7.1.4 Available? We get a Cross Site Scripting (XSS) vulnerability.

    #1494259

    Anyone?

    #1494260

    Hi

    I too have had a message about the 7.1.3 Enfold Cross Site Scripting (XSS) vulnerability

    Please advise

    Thank you
    Nick

    #1494330

    Hi,
    Still waiting for some feedback / solution…

    #1494347

    Looking forward to an update and/or hotfix as well, thank you.

    #1494351

    Hi!

    Rest assured that a fix will be included in the next version (7.1.4), which should be released soon. Thank you for your patience.

    Regards,
    Ismael

    #1495192

    I have had a Cross Site Scripting (XSS) vulnerability.
    New update? 7.1.4? When?

    #1495193

    All of you who are impatiently waiting for a fix. Have you ever tested your site on
    securityheaders.com, or on MDN Observatory for example?
    Please start by securing your pages against attacks in general and closing the huge gate to your pages before you try to plug small loopholes.

    #1495216

    Hi @Guenni007,
    reporting this warning… does not mean badmouthing “our” great “Enfold theme”. But you understand that seeing this warning every week for months and then having to explain to our users that it’s nothing serious… ugh… it gets embarrassing.
    Don’t you think?

    Best regards, Oriano

    #1495263

    Hey,
    When will the update be available? It’s been a couple of weeks now….
    I’m looking forward to your feedback / update.

    #1495269

    Hi!

    We have forwarded this thread to our channel again and you will be notified once the patch is released. Thank you all for your patience.

    Best regards,
    Ismael

    #1495284

    @Guenni007 Thanks for these links!
    What is a good score (for HTTP Observatory) and a good grade for Security Headers?

    #1495294

    by the way – i guess 7.1.4 is online !

    my values are A+ and 120/100. ;) yes that is possible with extra points on mdn observatory

    for wordpress pages with all its plugins you can not have better settings on style-src than ‘unsafe-inline’

Viewing 13 posts - 1 through 13 (of 13 total)
  • You must be logged in to reply to this topic.