Skip to content

blog.mozilla.org running vulnerable version of plugins #17298

Description

@data-sync-user

Hello folks, we received a report that blog.mozilla.org is using a vulnerable version of the plugin sitepress-multilingual-cms, the old versions are impacted by CVE-2024-6386 and CVE-2025-3488 which were fixed in versions 4.6.13 and 4.7.3.

Can you also please check if there is an update to wordpress which we can use?

┆Issue is synchronized with this Jira Task
┆Epic: Wordpress Maintenance

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions