-
Search Results
-
Topic: WordPress Enfold Theme
WordPress Enfold Theme <= 6.0.3 is vulnerable to Cross Site Scripting (XSS)
My hosts routine scan has highlighted Enfold <= 6.0.3 is vulnerable to Stored Cross-Site Scripting.
Is this already known about? If so, any idea on an update/fix? The JetPack ‘fix’ seems to remove Enfold and activate the default theme so probably not the best fix.
Enfold <= 6.0.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via wrapper_class and class Parameters
Description
The Enfold – Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and ‘class’ parameters in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.https://wpscan.com/vulnerability/92c563a1-acef-4191-b8ea-f6746ef0ee76/
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/enfold/enfold-603-authenticated-contributor-stored-cross-site-scripting-via-wrapper-class-and-class-parametersDear Sirs,
I am migrtaing my site over to a new doamin and get this error can you help me please,
Warning: include(/home/respectaclecompa/public_html/wp-content/uploads/avia_fonts/fontello/charmap.php): failed to open stream: No such file or directory in /home/respectaclecompa/public_html/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/php/class-font-manager.php on line 679
Warning: include(): Failed opening ‘/home/respectaclecompa/public_html/wp-content/uploads/avia_fonts/fontello/charmap.php’ for inclusion (include_path=’.:/opt/alt/php74/usr/share/pear’) in /home/respectaclecompa/public_html/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/php/class-font-manager.php on line 679
Dear Sirs,
I am migrtaing my site over to a new doamin and get this error can you help me please,
Warning: include(/home/respectaclecompa/public_html/wp-content/uploads/avia_fonts/fontello/charmap.php): failed to open stream: No such file or directory in /home/respectaclecompa/public_html/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/php/class-font-manager.php on line 679
Warning: include(): Failed opening ‘/home/respectaclecompa/public_html/wp-content/uploads/avia_fonts/fontello/charmap.php’ for inclusion (include_path=’.:/opt/alt/php74/usr/share/pear’) in /home/respectaclecompa/public_html/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/php/class-font-manager.php on line 679
Noted problem paging after searching with expressions that contain one of these words:
jpg, jpeg, gif or pngTo reproduce go to:
https://kriesi.at/themes/enfold-2017/?s=jpg
search on ‘jpg’
Go to bottom of page and try to navigate to page 2,
instead of going to page 2, it attempts to load on image in a light box.
Topic: Embed YouTube Video
Hello there,
we are using a textblock as a template for our client.
Within the textblock, there is a div and a list.The closingtag of the div will sometimes sit at the end of the whole page (outside of all the shortcodes). We don’t know how or why, but upon saving, the whole page gets purged after the text block (since there is an open div-tag, I suppose).
We do have the latest enfold version and also the latest WordPress update.We don’t know how the div gets outside the shortcodes, are you able to help? Is this a known bug? Are Divs not allowed within textblocks?
Topic: error message – wp_vul_xss
I am seeing this messge: https://imgur.com/SfsuRiq and something about wp_vul_xss in enfold
and it’s sending me here: https://app.patchstack.com/register
do you know anything about this?
My server is one.com
THanksHello
We have the problem that whenever we type a < or > character in a cell of the ALB table element, the output in the frontend no longer shows the table but only the shortcodes (see screenshots). If we enter the corresponding html entities instead, the problem does not occur.
Before entering <

After entering <

The problem also occurs in a brand new WP installation with Enfold 6.0.3.
Thank you very much for your support.
Viewing 30 results - 5,821 through 5,850 (of 244,023 total)
