Nexter Extension - PRO
1 day ago

Version 4.7.6

  • Improvement : Security : added missing file guards across 15 files and switched a token comparison to a timing-safe check
  • Fixed : Security : Media Replacement no longer lets a user read or permanently delete another user's attachment via a swapped ID
  • Fixed : Security : license activate/deactivate and notice-dismiss AJAX now require Administrator, not just a valid nonce
  • Fixed : Security : Admin Menu Organizer's "always hide for role(s)" now actually blocks the page server-side instead of only hiding the menu link
  • Fixed : Security : Admin Menu Organizer no longer permanently grants Contact Form 7 access down to Subscriber
  • Fixed : Security : the [nxt_encode] shortcode no longer accepts a javascript: link
  • Fixed : Security : "Hide Author URLs" now generates a truly random slug instead of one derived from the site's own public plugin URL
  • Fixed : Security : Local User Avatar no longer accepts an arbitrary attachment ID, and a crafted filename can no longer corrupt the output
  • Fixed : Security : 2FA code resend is now rate-limited and POST-only; recovery codes restored to a safe length
  • Fixed : two 2FA REST endpoints that always failed due to a wrong class/provider name
  • Fixed : Security : Settings Import now sanitises every imported value and no longer exports the license key

Discussion