Important: Serious Vulnerability in Revolution Slider & Showbiz Pro (WordPress) Plugins

@Natman: please remove our Book Your Travel - Online Booking WordPress Theme from the list of Potentially Affected Themes, because we have included the Revolution slider on 22.08.2014 using version 4.5.95, therefore we have never passed the old, vulnerable version to anyone.

Thank you.

What’s the reason for the list? My themes include latest version of RevSlider so why are they there?

btw, I have only one theme with LayerSlider and I’ve noticed quite noticeable sales increase for it.

hi,

I believe the list was automatically generated. As they mention, this is a list of possible affected themes ( my theme is in that list as well even if it’s not affected at all :slight_smile: ).

I think that the team is very busy now to check each theme to make sure the fix is included in the themes or not.

I think that all authors will suffer a decrease in sales after this message :(.

Best regards,
Stefan

Seriously, I’ve released new theme with RevSlider on Monday and it’s on the list… I understand it but you could think it through and at least compare the dates.

Hi guys, as stated in the blog post, the list contains all themes that reference either Revolution Slider or Showbiz Pro in their item description. We’ve taken a conservative approach due to the seriousness and urgency of the situation.

We’ll continue to update the list as we receive new information — i.e., confirmation themes do or don’t need to be there — from our developers. While we’ve made every effort to identify affected themes, if you’re an author of an affected theme not in the list please email me here.

The number one priority right now is that all affected buyers are aware of the situation and take necessary steps to protect themselves. Thanks for your patience and understanding.

natman said

Hi guys, as stated in the blog post, the list contains all themes that reference either Revolution Slider or Showbiz Pro in their item description. We’ve taken a conservative approach due to the seriousness and urgency of the situation.

We’ll continue to update the list as we receive new information — i.e., confirmation themes do or don’t need to be there — from our developers. While we’ve made every effort to identify affected themes, if you’re an author of an affected theme not in the list please email me here.

The number one priority right now is that all affected buyers are aware of the situation and take necessary steps to protect themselves. Thanks for your patience and understanding.

Hi,

just wanted to let you know that your link doesn’t work :slight_smile:

Best regards,
Stefan

ThemeFuzz said

Hi,

just wanted to let you know that your link doesn’t work :slight_smile:

Fixed it :slight_smile:

Hi,

My all three themes are in the list. All of them are updated with the newer version of Revolution Slider and are safe.

By the way, One of them was first released in June 2014 so I believe you don’t need to include themes which are released in April or later in this list.

Also, I think even if our older themes are updated with a newer version of Revolution Slider, you should send an email to our purchasers because it’s possible that some of them did not update their themes to the latest version.

Thanks!

Iman

ThemeFuzz said
||+1113079|Dream-Theme said-||
natman said
ThemesDepot said

Another proof that we should not be bundling plugins into our themes. When will Envato act in this matter?

Thanks for asking, ThemesDepot. As Collis said in the main post, “We are also going to revisit how updates are handled for bundles and themes that include separate plugins.”

Yep. Brilliant idea! Prohibit to use Visual Composer, Revolution and Layer Slider!.. but there may be a minor side effect: themes will stop selling.

This is not entirely true… Many authors have made their own frameworks and pagebuilders, as well as sliders plugins.

On a level , i would agree with limiting the authors on using these type of plugins, but only by the fact that an extended license is to cheap in my opinion. Many authors are making their themes solely based on this type of plugins ( for example, Visual composer ). There is very little input on what the author really does for a theme that includes these plugins ( coding wise ).

Best regards,
Stefan

Like it or not, but Visual Composer is de-facto became the industry standard. (And is promoted by Envato BTW.) Other builders are doomed. You can PM me in half a year if time will prove me wrong :wink:

ImanGM said

Hi,

My all three themes are in the list. All of them are updated with the newer version of Revolution Slider and are safe.

By the way, One of them was first released in June 2014 so I believe you don’t need to include themes which are released in April or later in this list.

Also, I think even if our older themes are updated with a newer version of Revolution Slider, you should send an email to our purchasers because it’s possible that some of them did not update their themes to the latest version.

Thanks!

Iman

Hi Iman! Absolutely understand about newer themes. We’re just erring on the side of caution but we’ll continue to update and maintain that list of possible, affected items. Thanks for your patience in the interim. Regarding contacting buyers via e-mail, we already have plans to do that. Thanks again!

Well, my theme “Fineliner” doesn’t include either Revolution Slider or Showbiz Pro plugins but why it’s in the list?

UXbarn said

Well, my theme “Fineliner” doesn’t include either Revolution Slider or Showbiz Pro plugins but why it’s in the list?

You have “Revolution Slider” phrase in your update history. It seems the list is automatically generated and grabbed all items with Revolution Slider words in their item description.

As @ScottWills said:

scottwills said

We’re just erring on the side of caution but we’ll continue to update and maintain that list of possible, affected items. Thanks for your patience in the interim.

Thanks Scott for reply :slight_smile:

Oh OK. Thanks Iman. :slight_smile:

ImanGM said

Hey Natalia,

I think if we have an option to leave a message to purchasers in our update notification email, 90% of the problem will be fixed as this issue was fixed by @ThemePunch in February but not so many people were informed about it.

Cheers,
Iman

Is bug still alive in new version 4.6 or removed in revolution slider. Please confirm me. I am too muh worries as my 5000+ user use it.

Thanks

SpyroPress said
ImanGM said

Hey Natalia,

I think if we have an option to leave a message to purchasers in our update notification email, 90% of the problem will be fixed as this issue was fixed by @ThemePunch in February but not so many people were informed about it.

Cheers,
Iman

Is bug still alive in new version 4.6 or removed in revolution slider. Please confirm me. I am too muh worries as my 5000+ user use it.

Thanks

The Bug is fixed back in February already in version 4.2. If you are on 4.2 or later, you are safe !

Everyone should pay attention to it.

Hi Folks,

we just put together a Tool/Plugin which helps you to identify if any action, like an urgent update need to be done. If you are not sure, or if you wish to have a tool installed which checks daily the status of your installed ThemePunch plugins, please download and install the “Punch-Guider” DOWNLOAD HERE.

This tool allows you to dynamically check the installed ThemePunch Plugins in your WordPress installation. If one of your plugin needs an update, recommended or critical, it will inform you about this fact. It does not update your plugins, but it helps you to keep an eye on the plugin status and informs you if there is any action that you need to take.

Thanks a lot,

ThemePunch

Why Envato is publishing this now if it was already fixed? Obviously it can affect sales… But isn’t relevant anymore (because authors fixed the problem already). I think in that case it would be better if Envato use email instead…

wpbakery said

Why Envato is publishing this now if it was already fixed? Obviously it can affect sales… But isn’t relevant anymore (because authors fixed the problem already). I think in that case it would be better if Envato use email instead…

Couldn’t agree more.

Bugs are everywhere since we’re talking about software and ThemePunch already fixed it months ago.

themepunch said

Hi Folks,

we just put together a Tool/Plugin which helps you to identify if any action, like an urgent update need to be done. If you are not sure, or if you wish to have a tool installed which checks daily the status of your installed ThemePunch plugins, please download and install the “Punch-Guider” DOWNLOAD HERE.

This tool allows you to dynamically check the installed ThemePunch Plugins in your WordPress installation. If one of your plugin needs an update, recommended or critical, it will inform you about this fact. It does not update your plugins, but it helps you to keep an eye on the plugin status and informs you if there is any action that you need to take.

Thanks a lot,

ThemePunch

Thanks @themepunch! This is a great way to help users even more :slight_smile:

Your Revolution Slider rocks!

@wpbakery: I don’t think it affect the sales as they have fixed this issue immediately even when nobody else was informed about it. People will understand that this is a great item and bugs are everywhere. The important thing is that they fixed it so soon and it shows their responsibility and excellent support :slight_smile:

Cheers,

Iman

P.S. May the the title of the thread should change to something like this:


Important: Vulnerability in Revolution Slider & Showbiz Pro (WordPress) Plugins - FIXED, Please Update!