Skip to content

Fixed Vulnerabilities reported by Wordfence

Latest

Choose a tag to compare

@rameezwp rameezwp released this 02 Oct 06:27
  • Security Fix: Stored XSS via frontend property submission (added nonce and capability checks, sanitized property meta, escaped price text output)
  • Security Fix: Users could overwrite posts they do not own through the frontend property form
  • Security Fix: Stored XSS via agent registration fields (registration data is now sanitized and escaped on the Agents admin page)
  • Security Fix: reCAPTCHA could be bypassed on agent registration, login and contact forms by omitting the captcha response
  • Security Fix: Agent passwords are no longer stored as plain text user meta on auto approved registrations
  • New Filter: rem_user_can_submit_property to allow custom roles to submit properties from frontend