Kadence Security Pro
Security
- Fixed SQL injection vulnerability in the logs page. Note: Admin privileges are required to exploit this vulnerability. Thanks to Çlirim Emini, Penetration Tester at sentry.co.com, for reporting this vulnerability.
Tweaks
- Recommend Strong Passwords and Refuse Compromised Passwords in the Grade Report.
Fixes
- Provide default values for enabled requirements.
Fixes
- Accessing password requirement settings would not resolve properly in some instances.
Tweaks
- Only pre-select Two-Factor methods during on-board process if the user requires Two-Factor. This should help prevent users from rolling through the on-board process too quickly.
- Show if a “force password change” is in-effect and allow for the change to be removed.
- Add debug settings JSON editor.
- If no last password change date is recorded for the user, treat their registration date as the last change date.
Fixes
- If a password requirement has been disabled or is no longer available, don’t consider the password as needing a change.
- Remove distributed storage table on uninstall.
- Don’t display backup Two-Factor method form if it is not available to the user. Previously it would only be prevented from being submitted.
Features
- Integration with Have I Been Pwned to prevent users from using passwords found in data breaches.
Tweaks
- Introduce Password Requirements module for managing and enforcing password requirements.
- Continually evaluate password strength for users instead of only during registration.
- Add basic admin debug page to help diagnosing and resolving issues. Particularly with the events.
Fixes
- Password strength would not be evaluated if password was set using custom PHP or CLI commands.
- Only hide “Acknowledge Weak Password” checkbox if the user was not allowed to use a weak password.
- Ensure Grade Report instructions in the Security Digest is accurate when the Grade score is capped.
Tweaks
- Add UI to cancel in progress File Scan.
- Improved rendering of the Grade Report grade pie chart on HiDPI screens.
- Include current grade in the Security Digest.
- Don’t write to the tracked files setting if the file hash has not changed.
- Exclude File Change storage settings from Importer/Exporter.
Fixes
- Ensure scheduling lock is cleared by the Cron Scheduler when not proceeding with running events.
- Away Mode would not lock out users who were already logged-in during the “away” period.
- Prevent File Change from getting stuck in an infinite rescheduling loop on the first step.
- Issue with Importing settings when File Change is active.
Fixes
- Fixed “Cannot modify header information – headers already sent” warning issue that could happen when using reCAPTCHA on sites that add customizations to the login page.
- Fixed an “Uncaught Error: Call to undefined function esc_like()” error that could occur when exporting or erasing personal data.
- Skip recovery if File Change storage is empty.
Features
- Added support for the new WordPress privacy features.
Tweaks
- Removed sending the remote_ip argument to Google’s reCAPTCHA server as it reduces the amount of personal information that is sent.
Fixes
- Changed the rules generated by the Filter Suspicious Query Strings feature in order to avoid blocking privacy export/erasure request confirmations.
Tweaks
- The number of users listed in the User Security Check model is now limited to 20 by default. This can be modified by using the itsec_user_security_check_users_per_page filter.
- Introduce Distributed Storage framework for reducing the amount of data stored in the WordPress options table. This should improve performance for large sites using File Change.
Fixes
- iThemes Licensing: Fixed fatal error that could occur when clicking the “View details” link for an available plugin update.
Tweaks
- Two-Factor Flow: Allow the user to proceed after downloading or copying the backup codes without dismissing the notice.
- File Change: Only scan a maximum of 10 plugins in a single chunk.
- File Change: Move “latest_changes” entry to a separate storage bucket to improve performance on large sites.
- iThemes Licensing: Added ability to manage licensing from WP-CLI.
Fixes
- Fix error on Multisite settings page when Two-Factor is not enabled.
- Properly enforce strong passwords when on the WP Login Reset Password page.
- Fix clearing or previous file scans results.
- iThemes Licensing: Fixed the “View details” link failing to work properly after updating.
- iThemes Licensing: Fixed an issue that could cause data changes to not save properly on specific background page requests.
- iThemes Licensing: Added a compatibility fix to avoid conflicts with plugins that change the plugin_action_links filter value from an array to a string.
- iThemes Licensing: Updated handing of wp_remote_get() response due to changes documented in https://core.trac.wordpress.org/ticket/33055.