Navigation überspringen

[Gelöst] Vulnerability in wp-views. Using vulnerable version of Select2 v4.0.3

This support ticket is created vor 4 months. There's a good chance that you are reading advice that it now obsolete.

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Zeitzone des Unterstützers: Asia/Kolkata (GMT+05:30)

Dieses Thema enthält 1 reply, hat 1 Stimme.

Zuletzt aktualisiert von Minesh vor 4 months.

Assistiert von: Minesh.

Author
Artikel
#2846780

Hi, please let me know if issue fixed. As mentioned in the earlier ticket issue will be fixed in early Feb 2026.

https://toolset.com/forums/topic/vulnerability-in-wp-views-using-vulnerable-version-of-select2-v4-0-3/#post-2844080

#2846811

Minesh
Unterstützer

Sprachen: Englisch (English )

Zeitzone: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

As I already inform you with the previous ticket with the following reply:
- https://toolset.com/forums/topic/vulnerability-in-wp-views-using-vulnerable-version-of-select2-v4-0-3/#post-2844080

Important facts:
- It is not exposed to anonymous users
- Inputs are controlled and sanitized - so you will not have to worry
- No escapeMarkup: false usage with user input

We already worked on this issue and updated the select2 version and the same updated hotfix version we suppose to release in one or two weeks. Probably next week if everything goes and works as expected.