Solid Security
Fixes
- Don't require "Write to Files" to be enabled to use the "Rotate Encryption Key" tool.
Tweaks
- Enforce encryption for Two-Factor secrets.
- Add Stellar and Solid banners.
Fixes
- Fallback to the homepage when Enforce SSL encounters a non-safelisted redirect destination.
- IP Detection on sites behind Load Balancers that appended their IP address to X-Forwarded-For and did not provide a Real IP header.
Fixes
- Update Password Strength library to the latest version. This fixes discrepancies between the realtime password strength estimation and the enforced password strength.
Security
- Prevent open redirects attacks against the Enforce SSL module. This attack requires spoofing the Host header which requires additional conditions to exploit. Thanks to nlpro for reporting the issue. Read More: https://ithemes.com/?p=84309
Tweaks
- Add "All" tab to the Features page.
- Don't show "Ban" buttons in Security Dashboard if the user won't be able to create a ban.
Fixes
- Prevent Headers Already Sent warning when a lockout occurs during a WP Cron request on some server setups.
- Manually load Sodium Polyfill for servers that have an older version of libsodium installed.
- Error when saving the File Change settings when the "notify_admin" setting was set.
- Prevent a redirect loop when logging in on sites that take more than 5 seconds to load the Dashboard.
Fixes
- File Logs not rotating.
- PHP warning when loading Icon Fonts in certain configurations.
- Don't attempt to Hide Backend when a Cron request is being processed.
- Prevent entering invalid date values when selecting a custom date range in the Security Dashboard.
- Preliminary PHP 8.1 compatibility.
- File Change "notify_admin" settings validation error.
Tweaks
- iThemes Security now requires PHP 7.3 and WordPress 5.9 or later.
- Add "Ban Lockout" button to the Active Lockouts card.
- Thanks to Calvin Alkan for reporting the security issues fixed in this release.
Security
- Add support for encrypting Two-Factor Mobile App secrets. Enable via Tools -> Set Encryption Key.
- Deprecate Automatic Proxy Detection. Instead, manually configure Proxy Detection or use Security Check. Fix IP spoofing attacks.
Tweaks
- Require a Title when creating a new Dashboard.
Fixes
- Don't attempt to send a Site Scan notification for Clean scans preventing a fatal error after scheduled site scans.
Fixes
- Error when visiting the Notifications page after activating a module with notifications for the first time.
- Update deprecated withState usages to useState.
Features
- Include the full iThemes Security Site Scanner in iThemes Security Free. Scheduled scans are disabled by default.
Fixes
- Scroll to top of window when navigating.
- Allow searching for Password Requirements.
- Don't load WordPress and System Tweaks modules when the
ITSEC_DISABLE_MODULESconstant is enabled. - Prevent incidentally loading the Two-Factor module when it is unregistered.
- Conditionally display the NGINX File Path setting.
- Allow saving Notifications when "default recipients must contain at least 1 item" error is present.
- Help styling on WordPress 5.9.
- Compatibility with plugins that expected a logged-in user during lockouts.
Tweaks
- iThemes Security now requires WordPress 5.8 or later.
- Add new "Go Pro" page that includes an overview of features in iThemes Security Pro.
Features
- Reintroduce Feature Flags management UI.
Fixes
- When the Change Admin User tool is run, update any User Groups referencing the old user id.
- WordPress footer would appear in the middle of the logs page.
- Add missing translation strings file.
Tweaks
- Reposition "Advanced" and "Tools" menu items to be more readable on lengthy screens.
Fixes
- Sites that did not support HTTPS, but had the SSL module active, but not configured, on upgrade would get redirected to the HTTPS version of the site.
- Unregister the iThemes Security Two-Factor module when the Two-Factor Feature Plugin is enabled.
- Allow activation on WordPress 5.7.0.
- Add missing textdomains.