توضیحات
از وبسایت خود با افزونه امنیت کامل وردپرس (AIOS) محافظت کنید - یک افزونه امنیتی جامع و آسان برای استفاده که مخصوص وردپرس طراحی شده است.
تغییرات این نسخه
5.4.9 – 5/Jun/2026
TWEAK: Added a filter that validates POST requests containing UDRPC messages
TWEAK: Update the internal common libs package to latest version
5.4.8 – 2/Jun/2026
SECURITY: Escaped debug log messages before rendering them in the admin area to prevent a stored XSS vulnerability. Thanks to Dmitrii Ignatyev for disclosing this defect. (This issue required both the debug logging feature and the “Disallow unauthorized REST API requests” setting to be enabled. Under those conditions, an attacker could inject malicious scripts into the debug logs via specially crafted requests, which could execute when viewed by an administrator on the AIOS debug logs page).
FEATURE: Add notification method to reporting class to handle mails
FEATURE: Added bulk actions to audit log table for blacklisting IPs
FIX: Fixed minor bug when setting up TFA with the Onboarding wizard where correct codes are rejected if they are entered more than once.
FIX: Log out button/link not working immediately after enabling the rename login feature
FIX: On the dashboard page, the login summary for a subsite in a multisite environment incorrectly shows details from the main site.
FIX: PHP Warning: Undefined global variable $hook_suffix in class-wp-screen.php when doing ajax table actions.
FIX: Properly decode the URI for the ‘advanced character filter’ in order to handle UTF-8 encoded URIs.
FIX: Resolve spammer IP address bulk block action not working issue.
TWEAK: Introduced .htaccess ve
TWEAK: Added a filter that validates POST requests containing UDRPC messages
TWEAK: Update the internal common libs package to latest version
5.4.8 – 2/Jun/2026
SECURITY: Escaped debug log messages before rendering them in the admin area to prevent a stored XSS vulnerability. Thanks to Dmitrii Ignatyev for disclosing this defect. (This issue required both the debug logging feature and the “Disallow unauthorized REST API requests” setting to be enabled. Under those conditions, an attacker could inject malicious scripts into the debug logs via specially crafted requests, which could execute when viewed by an administrator on the AIOS debug logs page).
FEATURE: Add notification method to reporting class to handle mails
FEATURE: Added bulk actions to audit log table for blacklisting IPs
FIX: Fixed minor bug when setting up TFA with the Onboarding wizard where correct codes are rejected if they are entered more than once.
FIX: Log out button/link not working immediately after enabling the rename login feature
FIX: On the dashboard page, the login summary for a subsite in a multisite environment incorrectly shows details from the main site.
FIX: PHP Warning: Undefined global variable $hook_suffix in class-wp-screen.php when doing ajax table actions.
FIX: Properly decode the URI for the ‘advanced character filter’ in order to handle UTF-8 encoded URIs.
FIX: Resolve spammer IP address bulk block action not working issue.
TWEAK: Introduced .htaccess ve