VirtueMart 3.2.6 has been released to address a minor XSS vulnerability present in previous versions as well as improve the infrastructure. It occurred when the features feeds and search were used together. It happened only for feed enabled, so administrators can close the leak by disabling the feed functions.

The vulnerability has been addressed by using getCurrentUrlBy function, which works with a whitelist for variable names and it urlencodes any value.


DOWNLOAD VM3 NOW
VirtueMart 3 component (core and AIO)

VirtueMart 3.2.6 Improvements


View full list of changes here

Thanks for reading!