Kadence Security Pro
Tweaks
- iThemes Security is becoming Solid Security soon. Learn More: https://go.solidwp.com/security-wpadmin-ithemes-becoming-solidwp
Fixes
- Username First login compatibility with WordPress 6.3.
Fixes
- Passwordless Login compatibility with WordPress 6.3.
Tweaks
- Add support for mandating User Verification when using passkeys.
Fixes
- Don’t require “Write to Files” to be enabled to use the “Rotate Encryption Key” tool.
Tweaks
- Kick off staged rollout of encryption.
Tweaks
- Start enabling encryption for existing iThemes Security sites. Read more: https://ithemes.com/?p=84653
Fixes
- Fallback to the homepage when Enforce SSL encounters a non-safelisted redirect destination.
- IP Detection on sites behind Load Balancers that appended their IP address to X-Forwarded-For and did not provide a Real IP header.
Security
- Prevent open redirects attacks against the Enforce SSL module. This attack requires spoofing the Host header which requires additional conditions to exploit. Thanks to nlpro for reporting the issue.
Features
- Add support for CloudFlare Turnstile and hCaptcha. Learn More: https://ithemes.com/?p=82867
Tweaks
- Add support for logging in with Discoverable Passkeys.
Fixes
- Update Password Strength library to the latest version. This fixes discrepancies between the realtime password strength estimation and the enforced password strength.
- Upgrade the iThemes Updater to 1.7.2 to fix PHP 8 issues.
Deprecateds
- Remove Grade Report.
Tweaks
- Add “All” tab to the Features page.
- Don’t show Passkeys onboarding flow during front-end Passwordless Login attempts.
Fixes
- Properly render the Passwordless Login block when not using a Full Site Editing theme.
- Prevent a redirect loop when logging in on sites that take more than 5 seconds to load the Dashboard.
Features
- Passwordless Login can now be setup from the frontend of your website. Use the new iThemes Security block in the Block Editor or the [itsec_passwordless_login_settings] shortcode.
Tweaks
- Don’t show “Ban” buttons in Security Dashboard if the user won’t be able to create a ban.
Fixes
- Prevent Headers Already Sent warning when a lockout occurs during a WP Cron request on some server setups.
- Manually load Sodium Polyfill for servers that have an older version of libsodium installed.
- Error when saving the File Change settings when the “notify_admin” setting was set.
Security
- Add support for encrypting Two-Factor Mobile App secrets. Enable via Tools -> Set Encryption Key.
- Deprecate Automatic Proxy Detection. Instead, manually configure Proxy Detection or use Security Check. Fix IP spoofing attacks.
Tweaks
- Add “Ban Lockout” button to the Active Lockouts card.
- Delete passkeys that have been in the “trash” for seven days.
- Thanks to Calvin Alkan for reporting the security issues fixed in this release.
Fixes
- File Logs not rotating.
- MaxMind DB Lite not being automatically refreshed.
- PHP warning when loading Icon Fonts in certain configurations.