Viewing 30 results - 6,331 through 6,360 (of 244,526 total)
  • Author
    Search Results
  • Steve
    Participant

    My hosts routine scan has highlighted Enfold <= 6.0.3 is vulnerable to Stored Cross-Site Scripting.

    Is this already known about? If so, any idea on an update/fix? The JetPack ‘fix’ seems to remove Enfold and activate the default theme so probably not the best fix.

    Enfold <= 6.0.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via wrapper_class and class Parameters

    Description
    The Enfold – Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and ‘class’ parameters in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    https://wpscan.com/vulnerability/92c563a1-acef-4191-b8ea-f6746ef0ee76/
    https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/enfold/enfold-603-authenticated-contributor-stored-cross-site-scripting-via-wrapper-class-and-class-parameters

    #1465835

    In reply to: Custom CSS not working

    tried on another site using enfold as well:

    <span style=”color: red; font-size: 45px; font-weight: 900;”>test of red</span>

    inline style, font weight not applied just like on the first site. Something overriding that inline formatting maybe? Still getting that bookmark anomaly but it seems to happen some of the time but not always now. Oy.

    #1465831
    Mike
    Participant

    I have no idea what changes were made, all of a sudden I can’t access advanced layout editor on my new pages. I can confirm all of the toggles are off in Enfold > Layout Editor so that wasn’t messed with.

    • This topic was modified 1 year, 7 months ago by Mike.
    #1465830
    condonp
    Participant

    Dear Sirs,

    I am migrtaing my site over to a new doamin and get this error can you help me please,

    Warning: include(/home/respectaclecompa/public_html/wp-content/uploads/avia_fonts/fontello/charmap.php): failed to open stream: No such file or directory in /home/respectaclecompa/public_html/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/php/class-font-manager.php on line 679

    Warning: include(): Failed opening ‘/home/respectaclecompa/public_html/wp-content/uploads/avia_fonts/fontello/charmap.php’ for inclusion (include_path=’.:/opt/alt/php74/usr/share/pear’) in /home/respectaclecompa/public_html/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/php/class-font-manager.php on line 679

    • This topic was modified 1 year, 7 months ago by condonp.
    #1465829
    condonp
    Participant

    Dear Sirs,

    I am migrtaing my site over to a new doamin and get this error can you help me please,

    Warning: include(/home/respectaclecompa/public_html/wp-content/uploads/avia_fonts/fontello/charmap.php): failed to open stream: No such file or directory in /home/respectaclecompa/public_html/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/php/class-font-manager.php on line 679

    Warning: include(): Failed opening ‘/home/respectaclecompa/public_html/wp-content/uploads/avia_fonts/fontello/charmap.php’ for inclusion (include_path=’.:/opt/alt/php74/usr/share/pear’) in /home/respectaclecompa/public_html/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/php/class-font-manager.php on line 679

    • This topic was modified 1 year, 7 months ago by condonp.
    #1465828

    In reply to: Custom CSS not working

    Wow what is happening? This code is auto generating on all my Enfold sites now. Make any new page, enter anything and I get this:

    <p><span data-mce-type=”bookmark” style=”display: inline-block; width: 0px; overflow: hidden; line-height: 0;” class=”mce_SELRES_start”></span>dasdsadsadas</p>

    #1465819
    This reply has been marked as private.
    Robert Massart
    Guest

    Noted problem paging after searching with expressions that contain one of these words:
    jpg, jpeg, gif or png

    To reproduce go to:

    https://kriesi.at/themes/enfold-2017/?s=jpg

    search on ‘jpg’

    Go to bottom of page and try to navigate to page 2,

    instead of going to page 2, it attempts to load on image in a light box.

    #1465771
    Bikul
    Participant

    Hello,
    I embedded a YouTube Video here:

    It is the second one one the page (Mitarbeitende für Theresienhof in Mühlenrade gesucht)

    Why does it link extern to YouTube and does not show it in the page with navigation elements like here:

    Thanks for Feedback
    Bernd

    Hey Daniel,

    Thank you for the inquiry.

    Unfortunately, you cannot add these characters directly in the table, but you can use the Special Character Translation plugin to resolve this issue. For more details, please check the documentation here: Using Special Characters in Enfold.

    Best regards,
    Ismael

    #1465753
    emilconsor
    Participant

    Hello there,

    we are using a textblock as a template for our client.
    Within the textblock, there is a div and a list.

    The closingtag of the div will sometimes sit at the end of the whole page (outside of all the shortcodes). We don’t know how or why, but upon saving, the whole page gets purged after the text block (since there is an open div-tag, I suppose).
    We do have the latest enfold version and also the latest WordPress update.

    We don’t know how the div gets outside the shortcodes, are you able to help? Is this a known bug? Are Divs not allowed within textblocks?

    • This topic was modified 1 year, 7 months ago by emilconsor.
    #1465751

    Hey thomasg156,

    Thank you for the inquiry.

    Did you add the tracking code in the Enfold > Google Services > Google Analytics Tracking Code field? We would like to check the issue but we encountered a fatal error when we tried to login in to the site.

    Best regards,
    Ismael

    #1465750
    Munford
    Participant

    I am seeing this messge: https://imgur.com/SfsuRiq and something about wp_vul_xss in enfold
    and it’s sending me here: https://app.patchstack.com/register
    do you know anything about this?
    My server is one.com
    THanks

    blende64
    Participant

    Hello

    We have the problem that whenever we type a < or > character in a cell of the ALB table element, the output in the frontend no longer shows the table but only the shortcodes (see screenshots). If we enter the corresponding html entities instead, the problem does not occur.

    Before entering <
    Before entering <

    After entering <
    after entering <

    The problem also occurs in a brand new WP installation with Enfold 6.0.3.

    Thank you very much for your support.

    #1465746

    Hi,

    Thanks for the update. Are you using Elementor to create the page in question? If so then we cannot support or fix problem related to that, I would advise that you try using the elements which are available in the Enfold Layout Builder instead.

    Best regards,
    Rikard

    #1465745

    In reply to: H1-H6

    Hi,

    Thanks for letting us know. Please open a new thread if you should have any further questions or problems.

    Best regards,
    Rikard

    #1465744

    Hey koomo,

    Please try the following in Quick CSS under Enfold->General Styling:

    #yith-wcbk-booking-services-4250 {
      display: none; 
    }

    Best regards,
    Rikard

    #1465740

    In reply to: Question

    Hi,

    Thanks for the update, we’ll close this thread for now then. Please open a new thread if you should have any further questions or problems.

    Best regards,
    Rikard

    #1465739

    Hi hitrev,

    You can adjust the container width under Enfold->General Layout, so you don’t need the CSS in question. If you want to install a child theme, then you can download one here: https://kriesi.at/documentation/enfold/child-theme/

    Best regards,
    Rikard

    #1465736

    In reply to: Category page edits

    Hi,

    Please try the following in Quick CSS under Enfold->General Styling:

    .archive .sidebar_left .sidebar {
      display: none;
    }
    
    .archive .container .av-content-small.units {
      width: 100%;
    }
    
    .archive .sidebar_left .content {
      border-left-width: 0;
    }

    Best regards,
    Rikard

    #1465735

    Hey bemodesign,

    Please try the following in Quick CSS under Enfold->General Styling:

    .page-id-34 h3.av-rotator-container-inner .av-rotator-text-single {
      text-shadow: 2px 2px #ff0000;
    }

    Best regards,
    Rikard

    #1465733

    Hi,

    Thanks for letting us know. Please open a new thread if you should have any further questions or problems.

    Best regards,
    Rikard

    #1465731

    Hi,

    Thanks for the update, we’ll close this thread for now then. Please open a new thread if you should have any further questions or problems.

    Best regards,
    Rikard

    #1465730

    Hi,

    Great, I’m glad that you found a solution and thanks for sharing. Please open a new thread if you should have any further questions or problems.

    Best regards,
    Rikard

    #1465729

    Hi,

    Please try the following in Quick CSS under Enfold->General Styling:

    .av-special-heading-h1 .special-heading-border {
      display: none;
    }

    Best regards,
    Rikard

    #1465726
    westefan
    Participant

    Hi, on portfolio site everything created with Enfold elements works fine. But on ajax portfolio some elements doesn’t work: for example videos or several rows of columns. Any idea for that?
    Thanks, Stefan

    #1465720
    Rob – Press Wizards
    Guest

    From WordFence:
    Enfold <= 6.0.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via wrapper_class and class Parameters
    Description

    The Enfold – Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and ‘class’ parameters in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
    CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
    CVE CVE-2024-5061
    CVSS 6.4 (Medium)
    Publicly Published August 29, 2024
    Last Updated August 29, 2024
    Researcher stealthcopter

    See: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-themes/enfold/enfold-603-authenticated-contributor-stored-cross-site-scripting-via-wrapper-class-and-class-parameters

    #1465714

    I don’t see that option at all. I’m using the Default Editor. When I try to switch to the Advanced Editor, I get a blank empty page… nothing shows that was built on the page.
    All I see is this:

    Text BlockX
    ContentStylingAdvanced
    Text Block Styling
    Text Alignment
    Select the text alignment.

    Default
    Textblock Content Styling
    Select if the content of the textblock shall be displayed in 1 block or float in columns.

    Single Block
    Font Sizes
    Colors

    Please be specific where I should be. I am new to Enfold!
    Thank you

    #1465713
    Kevin Geoffrey
    Guest

    Howdy. Are you guys aware that WordFence has flagged the current version of Enfold (6.0.3) for security vulnerabilities? Hope you have a fix coming soon. Thanks.

    Enfold <= 6.0.3 – Authenticated (Contributor ) Stored Cross-Site Scripting via wrapper_class and class Parameters

    The Enfold – Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and ‘class’ parameters in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    #1465704

    In reply to: transparent header

    Hi,

    Please try the following in Quick CSS under Enfold->General Styling:

    .header_color .header_bg {
      background-color: transparent !important;
    }

    Best regards,
    Rikard

Viewing 30 results - 6,331 through 6,360 (of 244,526 total)