Home Forums WoodMart support forum Woodmart core security vulnerbility

Woodmart core security vulnerbility

Viewing 8 posts - 1 through 8 (of 8 total)
  • Author
    Posts
  • #469108

    kelly-0476
    Participant

    Hi, I’ve just purchased a woodmart licence for a clients site so I can update woodmart to the latest version, as wordfence is flagging that the Woodmart Core plugin has a security vulnerability. I’ve updated the theme to version 7.2.4 and woodmart core is on Version 1.0.30, however wordfence is still flagging the security vulnerability. I’ve checked in Appearance –> Install plugins and I can’t see an update for Woodmart Core here.. Please can you advise the latest version of Woodmart Core, and how I can update it?

    #469113

    Artem Temos
    Keymaster

    Hello,

    Thank you so much for purchasing our theme and contacting our support center.

    You can update the WoodMart core plugin via WordPress dashboard -> WoodMart -> Plugins. It should be 1.0.39.

    Kind Regards
    XTemos Studio

    #469539

    kelly-0476
    Participant

    Hi, thanks for your reply
    I’ve gone into Woodmart, and I can’t see an option for Plugins here. See attached screenshots. I also can’t see an update available when I go into Dashboard –> Updates
    Is there anywhere I can download a copy of the latest version of Woodmart Core and update it manually?

    Attachments:
    You must be logged in to view attached files.
    #469566

    Artem Temos
    Keymaster

    Hello,

    You need to update the theme to the latest version first. https://xtemos.com/docs-topic/update-the-theme/

    Kind Regards

    #469845

    kelly-0476
    Participant

    Hi, I’ve updated the theme to the latest version in Appearance –> Themes, it says it’s updated, but then when I refresh the page it’s asking me to update it again…
    Please can you confirm the latest theme version? I’m on 7.2.4 and I initially uploaded it manually after downloading it from themeforest a few days ago

    Attachments:
    You must be logged in to view attached files.
    #469857

    Artem Temos
    Keymaster

    Hello,

    Go to WordPress -> Update and click on the “Check again” button. The update notice will be removed.
    Yes, you have the latest version installed on your website now.

    Kind Regards

    #469878

    kelly-0476
    Participant

    Hi, I’ve managed to update the woodmart core plugin to the latest version, now on vs 1.0.35. Wordfence is still flagging a vulnerability, do you have any advice on this and when a patch will be released?

    Here’s the link from wordfence
    https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woodmart-core/woodmart-core-1036-missing-authorization-to-privilege-escalation

    #469929

    Artem Temos
    Keymaster

    Hello,

    If you have 1.0.39 version of the plugin then this issue no longer exists on your website. You can check the plugin version in WoodMart -> Plugins.

    Kind Regards

Viewing 8 posts - 1 through 8 (of 8 total)