[oik] plugins.com

WordPress plugins and themes

  • Home
  • About
    • lazy shortcodes
    • smart shortcodes
    • oik base plugin
      • oik – donate
      • oik PayPal buttons
      • oik installation
      • oik Button Shortcode button
      • oik changelog
      • oik FAQ
      • oik plugins on SVN
      • oik plugins on GitHub
  • Plugins
    • oik base plugin
    • FREE oik plugins
    • WordPress plugins
    • Premium oik plugins
    • Bespoke oik plugins
  • Shortcodes
    • Shortcode examples
  • Blocks
    • Block examples
  • APIs
    • ALL action and filter hooks
  • Blog

oik v4.10.2

Update to oik v4.10.2 for a security fix to prevent JavaScript in URLs.

oik base plugin banner

The security issue was responsibly disclosed by Wordfence. Vulnerability Researcher: Francesco Carlucci.

Vulnerability Title: oik <= 4.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CVE ID: CVE-2024-2256
CVSS Severity Score: 6.4 (Medium)
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Organization: Wordfence
Vulnerability Researcher(s): Francesco Carlucci

Description

The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s bw_contact_button and bw_button shortcodes and in all versions up to, and including, 4.10.0, due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Areas affected

The issue was reported against the following shortcodes [bw_contact_button] and [bw_button] when combined with the link attribute.

The fix also applies to the following shortcodes which were similarly vulnerable.

  • [bw_link]
  • [bw_logo]
  • [bw_qrcode]

What you should do

Update to oik v4.10.2 as soon as possible.

Changes

ChangeReference
Fixed: Escape the URL in links. bobbingwide/oik#224

oik v4.10.2 also includes previously unreleased changes in oik v4.10.1.

ChangeReference
Changed: Support PHP 8.3 bobbingwide/oik#220
Changed: Spam check subject for http bobbingwide/oik#221

Tested

  • Tested: With WordPress 6.4.3 and WordPress Multisite
  • Tested: With PHP 8.3
  • Tested: With PHPUnit 9.6
Version: 4.10.2
Plugin: oik – oik information kit
Required version: 5.0.3
Compatible up to: 6.5-RC1

Published: March 12, 2024 | Last updated: March 12, 2024

Information

Version: 4.10.2
Plugin: oik – oik information kit
Required version: 5.0.3
Compatible up to: 6.5-RC1
Download oik from wordpress.org
Download oik version 4.15.3
Download oik version 4.10.2

Plugins

  • All Plugins
  • oik base plugin
  • FREE oik plugins
  • WordPress plugins
  • Premium oik plugins

Themes

  • FREE themes
  • Bespoke themes
  • Premium themes

Blocks

  • All Blocks
  • Block examples
  • About Blocks

Shortcodes

  • All Shortcodes
  • Shortcode examples
  • About Shortcodes

Reference

  • About APIs
  • All APIs
  • All Classes
  • All Files
  • All Hooks

Support

  • Contact
  • Cookies policy
  • Get API key
  • Privacy
  • Request support
  • Sitemap
  • Stay informed
  • Terms and Conditions
oik-plugins
Email: oikplug@oik-plugins.com

Weight shipping plugins

Find out which cart weight shipping plugin you need for your WooCommerce site.
Which cart weight based plugin do I need?

Site:  www.oik-plugins.com
© Copyright oik-plugins 2011-2025. All rights reserved.


Website designed and developed by Herb Miller of Bobbing Wide
Proudly powered by WordPress and oik-plugins

WordPress version: 6.8.3

Gutenberg version: 21.7.0

PHP version: 8.2.29