Passer la navigation

[Résolu] Vulnerability in wp-views. Using vulnerable version of Select2 v4.0.3

This support ticket is created Il y a 4 months. There's a good chance that you are reading advice that it now obsolete.

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Fuseau horaire du supporter : Asia/Kolkata (GMT+05:30)

Ce sujet contient 1 reply, a 1 voix.

Dernière mise à jour par Minesh Il y a 4 months.

Assisté par: Minesh.

Auteur
Publications
#2846780

Hi, please let me know if issue fixed. As mentioned in the earlier ticket issue will be fixed in early Feb 2026.

https://toolset.com/forums/topic/vulnerability-in-wp-views-using-vulnerable-version-of-select2-v4-0-3/#post-2844080

#2846811

Minesh
Supporter

Les langues: Anglais (English )

Fuseau horaire: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

As I already inform you with the previous ticket with the following reply:
- https://toolset.com/forums/topic/vulnerability-in-wp-views-using-vulnerable-version-of-select2-v4-0-3/#post-2844080

Important facts:
- It is not exposed to anonymous users
- Inputs are controlled and sanitized - so you will not have to worry
- No escapeMarkup: false usage with user input

We already worked on this issue and updated the select2 version and the same updated hotfix version we suppose to release in one or two weeks. Probably next week if everything goes and works as expected.