Releases: BoldGrid/w3-total-cache
Releases · BoldGrid/w3-total-cache
Release list
2.10.5
Patch Release 2.10.4
- Fix: Lazy Load: Match only quoted image attributes when rewriting src/srcset/sizes
- Fix: Cache purge: Restore filterable capabilities for purge-all and purge-post
2.10.3
2.10.2
Patch Release 2.10.1
- Fix: General Settings: "The link you followed has expired" when emptying all caches
- Fix: Redis/Memcached/CDN: Restore connection handling after 2.10.0 at-rest credential encryption
- Fix: At-rest credentials: Defer encryption until WordPress salts are available
- Fix: Always Cached: Queue regeneration on Nginx with Disk: Enhanced page cache
- Fix: mfunc: Render unrecognized dynamic-fragment tags as empty output
- Fix: Apache: Remove Options -MultiViews from root .htaccess (HTTP 500 on restrictive AllowOverride)
- Fix: Multisite: Admin page links in network admin
Security Release 2.10.0
- Security: Hardened authorization, capability, and request-verification (nonce/CSRF) checks across admin and AJAX endpoints
- Security: Improved input validation and output escaping to prevent cross-site scripting (XSS)
- Security: Strengthened protections against code, command, and file-inclusion injection
- Security: Hardened processing of dynamic and cached content, including data serialization
- Security: Restricted outbound server-side requests to mitigate server-side request forgery (SSRF)
- Security: Restricted configuration changes to prevent unauthorized modification
- Security: Improved handling of stored credentials, cookies, and generated server-configuration files
- Security: Reduced potential information disclosure and improved security logging
Patch Release 2.9.4
- Fix: Output buffering: Reverted to the previous output buffering from 2.9.1
- Fix: Cloudflare: Token/Key validation
- Fix: Prevent mfunc processing bypass by user-agent
Patch Release 2.9.2
- Fix: Fragment Cache: mfunc arbitrary code execution vulnerablity
- Fix: Fragment Cache: mfunc dynamic output buffering fatal error
- Fix: Image Converter: broken access control
Patch Release 2.9.1
- Fix: Image Converter: Reset request when status is 404
- Fix: Image Converter: Better handling of separate format requests
- Fix: Image Converter: UI/JS changes
Feature Release 2.9.0
- Feature: Next-Gen AVIF image conversion (Pro)
- Feature: Added notices for some billing issues
- Fix: Bunny CDN purge section
- Fix: New Relic API
- Fix: Nginx + Memcached Unix socket compatability
- Update: Setup Guide Wizard and test improvements
- Update: WebP Converter renamed to Image Converter