Skip Navigation

[Resolved] Is polyfill . io used in the Toolset Maps plugin?

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Supporter timezone: Asia/Kolkata (GMT+05:30)

This topic contains 3 replies, has 2 voices.

Last updated by Minesh 6 months, 2 weeks ago.

Assisted by: Minesh.

Author
Posts
#2705825

We received the following notification from Google:
------------------------------------------------------------------------------------------------
[Security Alert]: Polyfill.io Issue for Google Maps Platform users
6/28/24, 7:03 PM
Hello Google Maps Platform Customer,
We're writing to let you know that a security issue may be affecting websites using specific third-party libraries (including polyfill.io).

What happened
We have become aware of a security issue that may be affecting websites using specific third-party libraries (including polyfill.io). This issue can sometimes redirect visitors away from the intended website without website owner knowledge or permission, or potentially cause other malicious behavior. Many of the Maps JavaScript API samples in the Developer Documentation previously included a polyfill.io script declaration. We have removed this from those samples. If you have used the Maps JavaScript API samples that contain this declaration, we recommend removing the declaration.

What to do
Please see below to learn how to take action, if needed:
Investigate your website: Check your website's code to see if you're loading any compromised libraries (including polyfill.io).
Remove or replace the code: If you find compromised libraries, consider:
Hosting a clean, secure version of the code yourself
Switching to an alternative library or provider
Removing the library if you don’t need it
Re-deploy your code through your regular process.
-------------------------------------------------------------------------------------------

The only place we're currently using Google Maps is in the Toolset Maps plugin on one of our websites. We're needing to determine if the plugins uses polyfill.io, and if so, will you be issuing an update to address this vulnerability?

Thank you for your help,
Barney Royalty
Focus on the Family

#2705851

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

I had a user who reported the same issue and here is that related ticket.

When I checked on internet I found few related topics which are reported recently in a day or two:
- https://wordpress.org/support/topic/google-maps-security-notification/
- hidden link
- https://wordpress.org/support/topic/security-alert-polyfill-io-issue-for-google-maps-platform-users/
- https://wordpress.org/support/topic/security-alert-polyfill-io-issue-for-google-maps-platform-users-3/

This might help you as well:
- hidden link
- hidden link

Please check the following related ticket:
- https://toolset.com/forums/topic/polyfill-warning-in-relation-to-google-maps/

#2705996

You did not answer my question.

Does Toolset Maps use polyfill.io?

If it does, will you be updating the plugin to remove the vulnerability?

#2706086

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Does Toolset Maps use polyfill.io?
===>
No - Toolset plugins do not use polyfill.io.