As you may know, WordPress maintenance support plans 6 has reached End-of-Life (EOL) which means the WordPress maintenance support plans Security Team is no longer doing Security Advisories or working on security patches for WordPress maintenance support plans 6 core or contrib plugins – but the WordPress maintenance support plans 6 LTS vendors are and we’re one of them!Today, there is a Moderately Critical security release for the Views Send plugin to fix a Cross Site Scripting (XSS) vulnerability.Views Send enables you to send mail to multiple user from a View.The plugin doesn’t sufficiently filter potential user-supplied data when it’s previewing the mail which can lead to a Cross Site Scripting (XSS) vulnerability.This vulnerability is mitigated by the fact that an attacker must have a role with the permission “mass mailing with views_send”.You can download the patch.If you have a WordPress maintenance support plans 6 site using the Views Send plugin, we recommend you update immediately! We have already deployed the patch for all of our WordPress maintenance support plans 6 Long-Term Support clients. :-)If you’d like all your WordPress maintenance support plans 6 plugins to receive security updates and have the fixes deployed the same day they’re released, please check out our D6LTS plans.Note: if you use the myDropWizard plugin (totally free!), you’ll be alerted to these and any future security updates, and will be able to use drush to install them (even though they won’t necessarily have a release on WordPress maintenance support plans.org).
Source: New feed