• ResolvedPlugin Author Rene Hermenau

    (@renehermi)


    WP Staging 4.14.0 is out.

    This is a maintenance release: security hardening and bug fixes across backups, staging sites and multisite.

    Fixes

    • Stop the backups folder running scripts on Apache and IIS.
    • Block IPv6 and DNS-rebinding bypasses of the backup download SSRF filter.
    • Generate job IDs with a secure random source so log stream tokens cannot be guessed.
    • Include schemes in copied backup links and CLI restore commands.
    • Preserve native Element.prototype.closest and only polyfill it when missing.
    • Prevent staging prefix reuse from destroying another staging site.
    • Redact the installation root inside failed-move warnings.
    • Refuse an invalid database table prefix when a staging site is saved, so pushing or resetting it cannot fail on it later.
    • Render the staging delete modal when the staging database is unreachable.
    • Report the latest log line, not the whole log, when a job responds before it has logged anything.
    • Stop logging a throttled request as an error during a healthy job.
    • Stop the backup schedule cron event from flooding the error log when WordPress cannot save the cron option, and prevent copied network schedules from running on other sites without disabling cross-site backup plans.
    • Stop the fatal error in the network admin when WP STAGING Free and WP STAGING Pro are both active on the main site.
    • Stop the scheduled-backup menu badge and cron warning from reporting a schedule row copied to a multisite subsite as overdue.

    Full changelog: https://wp-staging.com/wp-staging-changelog/

    • This topic was modified 19 hours, 36 minutes ago by Rene Hermenau.

You must be logged in to reply to this topic.