Nexter Extension - PRO
Version 4.7.6
- Improvement : Security : added missing file guards across 15 files and switched a token comparison to a timing-safe check
- Fixed : Security : Media Replacement no longer lets a user read or permanently delete another user's attachment via a swapped ID
- Fixed : Security : license activate/deactivate and notice-dismiss AJAX now require Administrator, not just a valid nonce
- Fixed : Security : Admin Menu Organizer's "always hide for role(s)" now actually blocks the page server-side instead of only hiding the menu link
- Fixed : Security : Admin Menu Organizer no longer permanently grants Contact Form 7 access down to Subscriber
- Fixed : Security : the [nxt_encode] shortcode no longer accepts a javascript: link
- Fixed : Security : "Hide Author URLs" now generates a truly random slug instead of one derived from the site's own public plugin URL
- Fixed : Security : Local User Avatar no longer accepts an arbitrary attachment ID, and a crafted filename can no longer corrupt the output
- Fixed : Security : 2FA code resend is now rate-limited and POST-only; recovery codes restored to a safe length
- Fixed : two 2FA REST endpoints that always failed due to a wrong class/provider name
- Fixed : Security : Settings Import now sanitises every imported value and no longer exports the license key