PluginUs.Net - Business Tools for WooCommerce and WordPress

[realize your idea - make your dreams come true]

Support Forum

You need to log-in to create request (topic) to the support

XSS?

The support doesn work on Saturdays and Sundays, so some Friday requests can be answered on Monday. If you have problems with registration ask help on contact us page please
If you not got email within 24~36 business hours, firstly check your spam box, and if no any email from the support there - back to the forum and read answer here. DO NOT ANSWER ON EMAILS [noreply@pluginus.net] FROM THE FORUM!! Emails are just for your info, all answers should be published only here.
The support doesn work on Saturdays and Sundays, so some Friday requests can be answered on Monday.

Hi,
so we just got a weird mail saying that your plugin seems somewhat connected to a xss vulnerability on a page we take care of.

I wonder if you could check this?
Is this legit or can we drop this as a scam?

*Domain: XXXXXXXXXXXX

*parameter affected : https://www.XXXXXXXXXXXX/de/mdtf-results-page/page/2?mdf_cat=

*payload : “>

*link of xss vulnerable URL: https://www.XXXXXXXXXXXX/de/mdtf-results-page/page/2?mdf_cat=x%22%3E%3CsvG%20onLoad=prompt(/xss/)%3E&page_mdf=4572&slg=

Hello

Please paste your license key here - https://share.pluginus.net/image/i20230222134241.png -> https://share.pluginus.net/image/i20230222134511.png

Update  the  plugin  to latest  version - https://wp-filter.com/howto/how-to-make-auto-update-for-wordpress-plugins-and-themes-bought-on-envato/