Support Forum

Advanced Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
general-topic
Simple Press - SQL Injection - Known Vulnerability
Avatar
Stan Dahl
Member
Offline
Jun 25, 2020 - 9:35 am

Hi,

For awhile now my website security plugin, iThemes Security Pro, has been reporting a serious security flaw in Simple Press.

  • Simple Press - SQL Injection

Is this something you are planning to fix soon?

Or is iThemes wrong to report this?

I'm a fan of Simple:Press and very much do NOT want to replace it with a different Forum option. 

I am also concerned about leaving my site open to malicious hackers.

Can you offer any guidance?

Avatar
SP Community Support
SP Moderator
Offline
Jun 25, 2020 - 2:13 pm

Hi:

We're not aware of vulnerability.  Usually, if a security researcher finds an issue they would report it privately to the software developer to give them a chance to fix the issue before going public with it.  So far we have not received any reports from iThemes.  Are you running version 6.5.1 of SP?  If you are then maybe they're reporting a false issue.

Thanks.

Avatar
SP Community Support
SP Moderator
Offline
Jun 25, 2020 - 2:21 pm

Does the scanner give you a file name or just the plugin name?

Avatar
Stan Dahl
Member
Offline
Jun 27, 2020 - 9:03 am

Only the plugin-in name.

No version. Which I've seen when other plugins are flagged, so I know they try to be specific.

I am not running the latest version. 

Makes sense i should upgrade and see if that changes anything.

Thanks.

Avatar
SP Community Support
SP Moderator
Offline
Jun 27, 2020 - 3:43 pm

Hi:

If you're running a version earlier than 6.3 you should upgrade.  I believe there was at least one security related fix in the 6.0 line.  Support and fixes ended for the 5.x line in 2019.

Please make sure you read the upgrade documentation if you are moving from V5 to V6.: https://simple-press.com/docum.....rsion-6-x/.

Thanks.

PS: End of life and deprecation polices and notices can be found here if it's the kind of thing that you're interested in: https://simple-press.com/depre.....-policies/

Avatar
Alex Morco
Rookie
Free Members
Offline
Sep 27, 2020 - 1:29 pm

All input fields are considered as the most common entry points for WordPress SQL Injection attacks. In Layman’s term, we can say:

Sign up forms
Login forms
Contact forms
Site searches
Feedback fields
Shopping carts

Avatar
Rose J Lever
Rookie
Free Members
Offline
Jan 11, 2023 - 6:50 am
Awaiting Moderation

Forum Timezone: Europe/Stockholm
Most Users Ever Online: 1170
Currently Online:
Guest(s) 1
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Mr Papa: 19448
Ike: 2086
Brandon: 864
kvr28: 804
jim: 650
FidoSysop: 577
Conrad_Farlow: 531
fiddlerman: 358
Stefano Prete: 325
Member Stats:
Guest Posters: 619
Members: 17362
Moderators: 0
Admins: 4
Forum Stats:
Groups: 7
Forums: 17
Topics: 10127
Posts: 79625