You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is the plugin in this GitHub repository the same as the one on the WordPress plugin page?
At a quick glance, I noticed that the source code and the code within the plugin are different. When downloading the plugin from the WordPress plugin page, it causes an SQL Injection Attack detection by OWASP.
Error: Message: Detected 200 (phase 2). Test 'REQUEST_COOKIES|!REQUEST_COOKIES:/__utm/|REQUEST_COOKIES_NAMES|REQUEST_HEADERS:User-Agent|REQUEST_HEADERS:Referer|ARGS_NAMES|ARGS|XML:/*' against '@detectSQLi' is true. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "66"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [logdata "Matched Data: sos found within sos: sos"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [MatchedString "sos"]
Source: /wp-content/plugins/trustpilot-reviews/review/assets/js/headerScript.min.js?ver=1.0'='async
Code differences
In Plugin page "trustpilot-reviews/review/Plugin.php":
Hey.
Is the plugin in this GitHub repository the same as the one on the WordPress plugin page?
At a quick glance, I noticed that the source code and the code within the plugin are different. When downloading the plugin from the WordPress plugin page, it causes an SQL Injection Attack detection by OWASP.
Error:
Message: Detected 200 (phase 2). Test 'REQUEST_COOKIES|!REQUEST_COOKIES:/__utm/|REQUEST_COOKIES_NAMES|REQUEST_HEADERS:User-Agent|REQUEST_HEADERS:Referer|ARGS_NAMES|ARGS|XML:/*' against '@detectSQLi' is true. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "66"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [logdata "Matched Data: sos found within sos: sos"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [MatchedString "sos"]
Source: /wp-content/plugins/trustpilot-reviews/review/assets/js/headerScript.min.js?ver=1.0'='async
Code differences
In Plugin page "trustpilot-reviews/review/Plugin.php":
Same point in this repository line:
plugin-woocommerce/Trustpilot/review/Plugin.php
Lines 133 to 156 in 908130b
This repo last update is 4 years ago. Plugin in Wordpress page last update 1 years ago.
What do you recommend to use?
Is the Woocommerce plugin in the Dashboard up to date and compatible with the latest WP installations?
--
Atte Oksanen // Mixerboy24
Jr Developer, ICT Tecnician
LocalghostFI
The text was updated successfully, but these errors were encountered: