@ma3ry
I have submitted a fix for this (Frontier Post ver 6.4, so I hope that the WordPress team will release the plugin very soon
I am sorry for the inconvenience this has caused
I have always made an effort to keep Frontier Post safe and secure, but I had made an error long time ago, that was found
I believe the risk of it being exploited is very low.
Thread Starter
ma3ry
(@ma3ry)
I am most grateful for your plugin. Thank you! And thank you so much for being so quick to respond. It is very much appreciated!!!!
I am using the plugin Frontier Post for almost 10 years now (in average 3 posts/week from my super-users). It always did the job very well. I would hate to have to replace it .
I started to look at the plugin directory (and paid plugins) and I found nothing that would do everything that Frontier Post Plugin does. The best contender would be User Submitted Posts https://wordpress.org/plugins/user-submitted-posts/ but it does not have edit of post after its publish (and no duplicate).The best paid one would be from CreativeMinds https://www.cminds.com/wordpress-plugins-library/cm-user-submitted-posts/ but it looks like the user can only access its own posts (and no duplicate).
@finnj
If the security issue was fix 2 months ago in version 6.4, can you not get WordPress team to diligently approved it and get it posted to the plugin directory.
Thanks again for the great plugin!
This plugin is risky and the developer does not release any updates. I don’t see any updates in my WP panel.0 So I’m looking for an alternative too. Delete this plugin immediately if you’re using it, if you don’t want any hassle in your website:
“The Frontier Post plugin for WordPress is vulnerable to attack in versions up to 6.1. This means that an unauthenticated attacker could trick a site administrator into clicking on a link, allowing them to perform an unauthorized action, such as changing settings or deleting data. The vulnerability is caused by incorrect or missing validation on a certain function.”
Thread Starter
ma3ry
(@ma3ry)
Good to know. Many thanks!