Solid Security
Features
- New Lockout Template screen.
Fixes
- Brute Force module reporting invalid logins using an email address incorrectly.
- Improve lockout compatibility with caching plugins.
- Fix admin notice not being dismissed due to a REST API route that was more narrowly defined than necessary.
- Admin Notices list did not refresh after dismissing a notice.
- Strong Passwords zxcvbn Library was not evaluating penalty strings correctly.
- Fix PHP warning if there are multiple detected proxy headers.
Tweaks
- iThemes Security requires PHP 5.4 or later.
- Add confirmation button to Login Interstitial Async Actions when on a different device.
- Add filter to “Lookup IP” link.
- There were significant changes to the internals of the iThemes Security Lockout API in this release. If you are using the ITSEC_Lockout class directly, all the API functions will continue to work, but will emit deprecation notices when legacy behavior is being used. Please update any integrations.
Tweaks
- New iThemes Sync Verb support for File Change.
- Add additional information about the login attempt when calling the Network Brute Force API.
Fixes
- Hide Backend Bypass.
- Strict Standards error during Sync request.
- wp_die() if a login interstitial session fails to be created instead of throwing a fatal error.
Tweaks
- iThemes Security Admin Notices are now conveniently located in the new Security Messages Menu. Check your notices in the Security menu on the WordPress Admin Bar.
- Add Security Message when a Notification Center email fails to send.
- Replace Trace IP with IP Tracker Online.
- Remove ‘DELETE’ method from “System Tweaks -> Filter Request Methods”
Fixes
- Hide backend bypass.
Fixes
- Hide Backend bypass on certain Apache configurations.
- Properly return error that occurs during a backup.
- Regex warning on PHP 7.3 in the File Change module.
- Resolve warning when a user is set to “No Role”.
Tweaks
- Allow the log description column to word break for URLs or other strings with no spaces.
Fixes
- Tabnapping: Apply noopener to links instead of using blankshield script when available to prevent new pop-up blocker behavior from killing the links.
Tweaks
- When ITSEC_DISABLE_MODULES is set, prevent hide backend from running.
Tweaks
- Add Per-Content SSL toggle to the upcoming Block Editor interface.
- Add filter to the recipients list for email notifications: “itsec_notification_{$notification}_email_recipients” and “itsec_notification_email_recipients”.
- Add define “ITSEC_DISABLE_TEMP_WHITELIST” to disable the Temporary IP Whitelisting for logged-in administrators.
- Improve redirecting after processing a login interstitial from a front-end login form.
- Add loopback IP detection to Security Check.
- Detect Server IPs in Security Check.
- Add additional safety checks when writing to system config files. This will log a “Critical Issue” when the writing of an empty or partial config file is detected and prevented.
- Improve File Change locking to help prevent failing scans on sites with inconsistent cron scheduling.
- Improve “System Tweaks – Suspicious Query Strings – SQLI” to reduce false positives.
- Improve “System Tweaks – Disable PHP” to block PHP files in apache configurations that serve files with a trailing dot.
- Remove “Seznam Bot” from HackRepair List as it isn’t present in the latest version.
Fixes
- Include Hide Backend token when emailing a password reset URL.
- Notification Center. Only send notifications to users with an exact role match of selected roles instead of a fuzzy match based on selected capabilities.
- Error when trying to edit reusable blocks with per-post SSL enabled.
- Resolve warnings on PHP 5.2.
Tweaks
- Allow for selecting the particular Proxy header a server is configured to use. Improve the language to indicate the importance of configuring this setting. H/t Filippo Cavallarin CEO at wearesegment.com
- Block access to git and svn repositories when System Tweaks -> Protect System Files is enabled.
- Update jQuery Validation library to 1.17.0
Fixes
- Improve detection of blocking the File Change Scan from being scheduled if one is already being run.
- Prevent infinite recursion error when trying to access directories outside of the allowed file tree.
Features
- Allow for globally setting recipients for admin-targeted notifications. All new notifications will default to the recipients in this list. Notifications can be set to use the default list or switch to a custom list.
Fixes
- 404 detection for plugins that mark is_404 later in the hook sequence.
- REST API Protection blocked the Taxonomies route for all users.
- Account for any CLI PHP SAPI instead of just WP-CLI in the SSL Module.
- Fixed how the Grade Report enable/disable status is stored to fix admin page loading issues on some sites.
- Fix serialization of closure error when a plugin registering a hook with a closure is in the boot-up stack and the notification center is triggered too early in the cycle.
Tweaks
- Added a setting to enable/disable the Grade Report feature of Pro.
- Check if an IP is blacklisted on page load for compatibility with servers that cannot process server configuration level bans immediately.
- Display a time diff until the next event on the Debug page.
- Use Logging API for tracking Notification Center errors.
- Register Scheduler Events whenever the plugin build changes.
- Allow for filtering logs by any module recorded.
- Account for 3rd-party Backup Plugin in Security Check.
Fixes
- Improved input sanitization on the logs page to prevent triggering warnings.
Security
- Add mitigation for the WordPress Attachment File Traversal and Deletion vulnerability.
Tweaks
- Fire a WordPress action whenever settings are updated.