Releases: codebard/patron-button-and-widgets-by-codebard
Releases · codebard/patron-button-and-widgets-by-codebard
Release list
2.3.1
= 2.3.1 =
- Security: Sanitized
$_REQUESTdata withmap_deep()before dispatching to action handlers - Security: Escaped all remaining unescaped variable and option outputs across admin pages
- Security: Escaped nonce, internal ID, and admin URL outputs in setup and settings templates
- Security: Added
wp_kses_post()escaping to language selector, addon display, and notice outputs - Security: Used targeted
wp_kses()allowlist for form/page template output to preserve form structure - Fix: Setup modal no longer renders raw PHP code from
$site_accountassignment outside PHP tags - Fix: Settings save restored after
wp_kses_post()mangled form HTML in page templates
2.3.0
= 2.3.0 =
- Security: Added capability check to setup wizard endpoint
- Security: Added sanitization to settings saved during setup wizard
- Security: Added escaping to
$_REQUESTparameter in setup modal JavaScript output - Security: Escaped all customizable language string outputs across admin pages
- Security: Replaced raw SQL string concatenation with
$wpdb->prepare()ininsert_single_c() - Security: Added
wp_kses_post()escaping to action dispatcher output
2.2.9
= 2.2.9 =
- License declaration corrected to GPLv2 or later
- Nonce verification added for settings tab form submissions
- SQL whitelist validation added to delete functions to prevent arbitrary table access
- Outputs in language settings escaped
- Outputs in setup modal escaped
- Outputs in pro pitch modal escaped
2.2.5
2.2.4
2.2.2
2.2.1
2.2.0
= 2.2.0 =
- Settings tab resetting & going to dashboard when saving a setting was fixed
- An issue with settings tabs not working correctly was fixed
- An issue with cross site scripting vulnerability was fixed
- Various forms and actions had security nonces added
2.1.9 release
= 2.1.9 =
- Added extra sanitization for security
2.1.8 release
= 2.1.8 =
- Fixed a bug that could prevent WP cli used in managed hosting services from failing in certain tasks
- Addressed a PHP warning
- Sanitized setup modal's site_account input