Okay
  Public Ticket #3557417
Theme Vulnerability and in need of patch
Closed

Comments

  • designtheory started the conversation

    Hello and good day!

    One of our clients is using this theme on their website and our management software has identified a vulnerability and we are hoping to get a patch/update from you. 

    vulnerable to Cross Site Scripting (XSS). Source here


  •  1,649
    Judith replied

    Hi there,

    Thanks for writing back.

    From the link, it refers to Salient Core version 2.0.2 and now we are at version 2.0.4. I would request you ensure that you update the Salient theme to the latest version and then also update the Salient plugins.

    If you have any further questions or need additional assistance, don't hesitate to write back, I'm happy to help. 


  •  8,406
    Tahir replied

    Hey Again,

    Please update to the Latest Salient Theme Version.

    The current version of the theme is 16.1.2 and the current version of the page builder is 6.7.1 . Salient versions older than v11 won't be compatible with WordPress 5.5.

    Here's the documentation on the available methods for updating Salient: http://themenectar.com/docs/salient/updating-salient/#methods Once you've updated that, the update for the included page builder will become available. Note that "Visual Composer" also renamed their plugin on Envato to "WPbakery page builder" a couple of years back.

    Here's an update guide on what to expect when jumping many major releases at once: http://themenectar.com/docs/salient/important-salient-update-for-new-envato-requirements/ take a read through before the update, as many things have changed.

    To get a list of Bug Fixes and new Feature addons in the Latest Theme updates view change log here http://themenectar.com/changelogs/salient.html .

    Thanks.


    ThemeNectar Support Team 

  •  1
    evebarth replied

    Hello, I have been trying to update my wordpress site with Salient Core 2.03 because of a security warning issue with the 1.9 version, but I can't find the Salient Core 2.03 plugin download, please help

  •  1,649
    Judith replied

    Hi there,

    Thanks for writing back.

    You can't individually download the Salient Core plugin as it is bundled with the Salient theme however ensuring the theme is up to date should be able to prompt updates also for the Salient plugins.

    I hope this clarifies. 

    Should you have any further questions or encounter any issues, please don't hesitate to reach out.

    Best regards,

  •  1
    evebarth replied

    Thank you, I'v tried to update by downloading and installing the new theme, I'v paid my license, but still it doesn't work. Wordpress continues to complain about Salient Core. I have installed the Envato Plugin, but it doesn't update Salient Core. What should I do ? Completely remove The Salient Theme and all its plugins and re=install frrom scratch ?

    Attached files:  Salient-Core-vulnerability.JPG

  •  8,406
    Tahir replied

    Hey evebarth ,

    You need to first install the Salient Theme and then update the Bundled Plugins that includes Salient Core: https://themenectar.com/docs/salient/installing-plugins-updated/

    Thanks.


    ThemeNectar Support Team 

  •  1
    evebarth replied

    Hello, I finally decided to delete the Salient Theme and all the plugins, Salient Core etc. Then re-uploaded the recent uncompressed Salient folder to the themes folder with FTP and reinstalled all plugins, and now it works

    The Envato plugin was unable to correctly handle the upgrade

    Best regards