Security Vulnerability Affecting prettyPhoto jQuery Script

bahemian said

Hey Stephan,

I’ve updated my theme which is using WooCommerce two days ago including PrettyPhoto 3.1.6 but still got the mail. why?

Cheers
Bahemian

Hi Bahemian,

That’d be because you didn’t add “prettyPhoto XSS fix” in the notes. :slight_smile:

Can you please re-upload it with "prettyPhoto resubmit” in the notes and one of the reviewers will check just that issue. Thanks.

Cheers,
Stephen

Hello Stephen,

I just got the email and my latest theme ‘Lines’ is in the list. Theme uses prettyPhoto version: 3.1.6 (VC plugin is not included); so I hope that Lines theme won’t be disabled.

Thank you
Daniel

LSVRthemes said

Hi Stephen,

as @theAlThemist and @bahemian noted, there is probably an issue with your system. I received notification for two of my items. One (BeautySpot) haven't been updated yet (I've submitted an update few minutes ago), but the second (Blue Collar) was actually updated almost week ago.

I have a VERY bad feeling that after 1st July, forums will be full of angry authors with unfairly disabled items... So please, double check before you disable an item.

Lubos

Hi Lubos,

I just checked and that’s because you didn’t include the “prettyPhoto XSS fix” string in the notes as requested. :slight_smile:

Can you please re-upload it with “prettyPhoto resubmit” in the notes and one of the reviewers will check just that issue. Thanks.

Note, we know that some people won’t have added the string or may have updated before we sent the email, which is why we are asking for people to upload with the note again if they think they shouldn’t have got the email. We want to minimize the risk of disabling themes that may have already been fixed. We don’t want that to happen (and I’m sure authors don’t want that either)!

Cheers,
Stephen

Hello,
Got the email about one of our plugin: http://codecanyon.net/item/woocommerce-products-designer/7818029. I did not replied the first time because i though it was a general notice for all authors. Now i got an email saying that they will disable that plugin if we don’t update our code. The thing is we don’t use that library. Even if you search prettyphoto in our code you won’t find any occurence. So why am i getting this?

Sorry, my bad! I will resubmit with that string asap.

By "notes" you mean "Message to the Reviewer", right?

Hi,

so yes I updated over 20 themes last week but didn’t include that string (didn’t even notice it tbh). So I have to update all themes again now with that string or they will all be disabled?

Hey StephenCronin, got the same email like other authors.

  1. One of our items ( HTML Template ) that doesn’t use prettyPhoto at all but the email included it which I believed your file search tool working incorrect.

  2. One of our WP theme that use Visual Composer already updated few days ago, of course it use VC 4.5.3, the theme doesn’t use prettyPhoto.

What I need to do in this case?

When re-upload the item, do I need to upload the file or just paste the message " prettyPhoto resubmit " and submit ? ( Because I already do that and the review auto approved : http://screenshots.wpcharming.com/image/0W3S3L1d3Y0J)

Regards.

Dannci said

Hello Stephen,

I just got the email and my latest theme ‘Lines’ is in the list. Theme uses prettyPhoto version: 3.1.6 (VC plugin is not included); so I hope that Lines theme won’t be disabled.

Thank you
Daniel

Hi Daniel,

Sorry, I know this is a hassle, but can you please re-upload it with “prettyPhoto resubmit” in the Message to Reviewer field? That will get it back in front of a reviewer, to double check it, so we can get it crossed off the list.

Cheers,
Stephen

LSVRthemes said

Sorry, my bad! I will resubmit with that string asap.

By "notes" you mean "Message to the Reviewer", right?

Yes - sorry about that - it is the Message to Reviewer field.

gljivec said

Hi,

so yes I updated over 20 themes last week but didn’t include that string (didn’t even notice it tbh). So I have to update all themes again now with that string or they will all be disabled?

Hi John,

Yes, I know this is a hassle, especially for 20 themes, but can you please re-upload them with “prettyPhoto resubmit” in the Message to Reviewer field? That will get it back in front of a reviewer, to double check it, so we can get it crossed off the list.

Cheers,
Stephen

Hi StephenCronin
We uploaded fixed version on June 19 and as you mentioned we resubmitted with word “prettyPhoto resubmit fixed on June 19” without uploading theme files.
But it does not appear in sidebar that “new update” "Queued for Review"
Do we need to reupload all files again?
Thanks,
SoapTheme

Hi there!
What if I forgot to mention “prettyPhoto XSS fix” in the notes? Where can I send the info about the updated items?

StephenCronin said
Dannci said

Hello Stephen,

I just got the email and my latest theme ‘Lines’ is in the list. Theme uses prettyPhoto version: 3.1.6 (VC plugin is not included); so I hope that Lines theme won’t be disabled.

Thank you
Daniel

Hi Daniel,

Sorry, I know this is a hassle, but can you please re-upload it with “prettyPhoto resubmit” in the Message to Reviewer field? That will get it back in front of a reviewer, to double check it, so we can get it crossed off the list.

Cheers,
Stephen

It is necessary to re-upload whole theme package, or it is enough to upload just thumbnail and add “prettyPhoto resubmit” note?
I’m asking 'cos I’m on the go these days and it is bit complicated to re-upload whole theme package.

Thank you

orionorigin said

Hello,
Got the email about one of our plugin: http://codecanyon.net/item/woocommerce-products-designer/7818029. I did not replied the first time because i though it was a general notice for all authors. Now i got an email saying that they will disable that plugin if we don’t update our code. The thing is we don’t use that library. Even if you search prettyphoto in our code you won’t find any occurence. So why am i getting this?

Hey Orionorigin,

We only sent this email (and the previous one) to people with items that we found prettyPhoto in.

You have prettyPhoto in WooCommerce in your demo (see screenshot). That’s probably less risk than it being in the plugin itself, but you never know what buyers will do with that. Can you please update that to use the latest version of WooCommerce (which has fixed it) or just replace those 2 files with the latest.

Thanks,
Stephen

WPCharming said

Hey StephenCronin, got the same email like other authors.

  1. One of our items ( HTML Template ) that doesn’t use prettyPhoto at all but the email included it which I believed your file search tool working incorrect.

  2. One of our WP theme that use Visual Composer already updated few days ago, of course it use VC 4.5.3, the theme doesn’t use prettyPhoto.

What I need to do in this case?

When re-upload the item, do I need to upload the file or just paste the message " prettyPhoto resubmit " and submit ? ( Because I already do that and the review auto approved : http://screenshots.wpcharming.com/image/0W3S3L1d3Y0J)

Regards.

Hi WP Charming,

  1. I checked that item and prettyPhoto is only in your documentation. That’s super unlikely to be exploited (users aren’t going to put the documentation on a live site, although there is a very small change that they may copy prettyPhoto to use elsewhere). Can you please update it anyway, just to be 100% safe?

  2. If the items isn’t mentioned on the list in the email, then you are okay. If it is mentioned, then re-upload with the note. If you haven’t made any changes to the zip file, it will auto approve, but we will be pulling a list of items with the exact phrase (“prettyPhoto resubmit”) to check.

Cheers,
Stephen

SoapTheme said

Hi StephenCronin
We uploaded fixed version on June 19 and as you mentioned we resubmitted with word “prettyPhoto resubmit fixed on June 19” without uploading theme files.
But it does not appear in sidebar that “new update” "Queued for Review"
Do we need to reupload all files again?
Thanks,
SoapTheme

Hi SoapTheme,

I can see you’ve uploaded both themes. Because you haven’t made any changes to the zip file, it will auto approve, but we will be pulling a list of items with the exact phrase (“prettyPhoto resubmit”) to check.

Cheers,
Stephen

mad_dog said

Hi there!
What if I forgot to mention “prettyPhoto XSS fix” in the notes? Where can I send the info about the updated items?

Hi mad_dog,

Just reupload it, leaving a note with the exact phrase “prettyPhoto resubmit” and stating the date of the previous update which fixed the issue.

Thanks!
Stephen

Dannci said
StephenCronin said
Dannci said

Hello Stephen,

I just got the email and my latest theme ‘Lines’ is in the list. Theme uses prettyPhoto version: 3.1.6 (VC plugin is not included); so I hope that Lines theme won’t be disabled.

Thank you
Daniel

Hi Daniel,

Sorry, I know this is a hassle, but can you please re-upload it with “prettyPhoto resubmit” in the Message to Reviewer field? That will get it back in front of a reviewer, to double check it, so we can get it crossed off the list.

Cheers,
Stephen

It is necessary to re-upload whole theme package, or it is enough to upload just thumbnail and add “prettyPhoto resubmit” note?
I’m asking 'cos I’m on the go these days and it is bit complicated to re-upload whole theme package.

Thank you

Hi Daniel,

I believe it is necessary to upload the item again to leave the note. I don’t think there is anyway around it. Sorry.

Cheers,
Stephen

So is it “prettyPhoto XSS fix” or “prettyPhoto resubmit”?

LSVRthemes said

So is it “prettyPhoto XSS fix” or “prettyPhoto resubmit”?

Hey LSVRthemes,

It’s all in the email. :slight_smile:

When submitting update that addresses this, please include the exact phrase "prettyPhoto XSS fix" in the notes. This makes it easier for us to identify these updates, allowing us to prioritise the review of updates relating to this issue.

If you believe you have already fixed these items, then please resubmit them, leaving a note with the exact phrase “prettyPhoto resubmit” and stating the date of the previous update which fixed the issue.

We treat those both differently - in the first case we’ll be doing a full review, while in the second case we will be checking that an update was submitted previously and then just verifying the prettyPhoto part.

Hope that makes sense?

Cheers,
Stephen