Skip Navigation

[Resuelto] Authenticated Arbitrary File Upload Vulnerability in Types

This support ticket is created hace 1 año, 8 meses. There's a good chance that you are reading advice that it now obsolete.

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Hoy no hay técnicos de soporte disponibles en el foro Juego de herramientas. Siéntase libre de enviar sus tiques y les daremos trámite tan pronto como estemos disponibles en línea. Gracias por su comprensión.

Este tema contiene 4 respuestas, tiene 2 mensajes.

Última actualización por Christopher Amirian hace 1 año, 8 meses.

Asistido por: Christopher Amirian.

Autor
Mensajes
#2565323

I got this warning today from my hosting provider about all of my sites that uses Toolset:

WordPress Toolset Types plugin <= 3.4.17 - Authenticated Arbitrary File Upload Vulnerability

Are you working on a resolution?

#2566233

Christopher Amirian
Supporter

Idiomas: Inglés (English )

Hi there,

As we did not have such a report before I'd appreciate it if you can ask for more details about the issue that is happening so we can investigate:

1. What is the issue and which file is involved.
2. Which tool they used to check and conclude that the issue is there,
3. Share with us the log of the issue and we will follow up

#2566287

The warning came from the hosting provider (InMotionHosting) and was attributed to their WP Toolkit. More details are available here where it also says the vulnerability has been reported to Toolset:

enlace oculto

#2566291

Christopher Amirian
Supporter

Idiomas: Inglés (English )

Thank you for that. I reported this to the second-tier and we will check this asap to see what is the issue.

#2566823

Christopher Amirian
Supporter

Idiomas: Inglés (English )

Hi there,

We have a new release with the fix implemented.

Please either go to https://toolset.com/account/downloads/ to download Toolset types version 3.4.18.
Or go to WordPress Dashboard > Plugins > Add New and click the "Check for Updates" button to see the new version to install.

Thank you.