Solid Security
Fixes
- Provide default values for enabled requirements.
Security
- Fixed SQL injection vulnerability in the logs page. Note: Admin privileges are required to exploit this vulnerability. Thanks to Çlirim Emini, Penetration Tester at sentry.co.com, for reporting this vulnerability.
Fixes
- Away Mode would not lock out users who were already logged-in during the “away” period.
- Enforce the Strong Passwords requirement during Security Check.
- Ensure scheduling lock is cleared by the Cron Scheduler when not proceeding with running events.
- If a password requirement has been disabled or is no longer available, don’t consider the password as needing a change.
- Only hide “Acknowledge Weak Password” checkbox if the user was not allowed to use a weak password.
- Password strength would not be evaluated if password was set using custom PHP or CLI commands.
- Prevent File Change from getting stuck in an infinite rescheduling loop on the first step.
- Remove distributed storage table on uninstall.
Tweaks
- Add UI to cancel in progress File Scan.
- Add basic admin debug page to help diagnosing and resolving issues. Particularly with the events.
- Add debug settings JSON editor.
- Continually evaluate password strength for users instead of only during registration.
- Introduce Password Requirements module for managing and enforcing password requirements.
- Accessing password requirement settings would not resolve properly in some instances.
- Don’t write to the tracked files setting if the file hash has not changed.
- If no last password change date is recorded for the user, treat their registration date as the last change date.
Fixes
- Fixed an “Uncaught Error: Call to undefined function esc_like()” error that could occur when exporting or erasing personal data.
- Skip recovery if File Change storage is empty.
Fixes
- Fixed situation that could cause lockout notifications being sent for whitelisted IPs.
- Fixed issue where saving Global Settings would be blocked by an unwritable “Path to Log Files” path when the “Log Type” is set to “Database Only”.
- Fixed issue that prevented log database entries from purging and log file entries from rotating on a schedule.
Security
- Fixed display of unescaped data on logs page. Thanks to Paweł Kuryłowicz from SecuRing for finding and reporting this issue.
Fixes
- The logging system now differentiates between WP-CLI commands, WP-Cron scheduled events, and normal page requests.
- Fixed the File Change scanner in that it previously could fail to exclude selected directories on some systems.
Tweaks
- Updated logging system to keep track of more information and have more options to filter and sort log entries.
- Improved efficiency of File Change Detection scanning.
Fixes
- Fixed issue that could register loading the logging page as a failed login attempt on some sites.
Fixes
- Load translations on the plugins_loaded hook.
- Fixed method that could be used to discover hidden login slug on some sites.
- Fixed issue that could prevent Sync from loading Malware Scan results if a scan previously failed.
- Update to the REST API “Restricted Access” feature to protect against methods to work around the restricted access.
- Prevent login page being hidden when following the “Confirm Email Address” notification URL.
- Hide Backend notifications not being properly sent when first enabled.
Tweaks
- Display user lockouts in Lockout Sidebar.
Deprecateds
- The ITSEC_FILE_CHECK_CRON and ITSEC_BACKUP_CRON constants have been deprecated. Use ITSEC_USE_CRON instead.
Features
- Introduces a scheduling framework for handling events. Cron is now used by default, and will switch to using an alternate scheduling system if it detects an error. To disable this detection set ITSEC_DISABLE_CRON_TEST in your wp-config.php file.
Fixes
- Preserve notification settings when the responsible module is deactivated.
- Process 404 lockouts on the ‘wp’ hook to prevent a headers have already been sent warning message.
- Ensure Hide Backend emails are properly sent when activating Hide Backend before saving the Notification Center for the first time.
- Prevent warning from being issued on new installs by allowing previous settings to be preserved if they exist.
- Better handle WP_Error objects in mail errors that occurred before updating to first patch release.
- A non static method was being called statically.
- Fix occasional duplicate backups and file scans.
- Fixed issue where scheduled events could repeat on sites that do not properly support WordPress’s cron system.
- Reactivating Away Mode now replaces the active file if you had previously removed it.
- Ensure lockouts take effect immediately, even on systems where changes to server configuration files do not take effect immediately.
Features
- Introduces the Notification Center, a centralized place to manage and customize email notifications sent by iThemes Security.
Fixes
- Corrected some Javascript and CSS links not generating correctly on Windows servers.
Tweaks
- Updated queries and prepare statements to account for changes to the esc_sql() function in WordPress 4.8.3.
Fixes
- Fixed SQL query bug that resulted in the “Minutes to Remember Bad Login (check period)” setting being ignored.
- Fixed bug that prevents wp-admin/install.php blocking from working properly on nginx servers.
- Don’t attempt to do an SSL redirect when WP CLI is running.