Zum Inhalt springen

Pods Updates & Release Notes

13 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 3.3.9.2: Umfassendes Sicherheitsupdate

Pods 3.3.9.2 ist ein umfassendes Sicherheitsupdate, das Display-Callbacks auf eine Allow-List sicherer Funktionen beschränkt (mit Admin-Hinweisen bei unzulässigen Callbacks), die Nonce-Behandlung in Formularen sowie Shortcode- und Block-Logik absichert und zwei Probleme des vorherigen Sicherheitsreleases bei post_status und anonymen Formular-Posts behebt.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 3.2.8.4: Umfassendes Sicherheitsupdate

Pods 3.2.8.4 ist ein umfassendes Sicherheitsupdate, das Display-Callbacks auf eine Allow-List sicherer Funktionen beschränkt (mit Admin-Hinweisen bei unzulässigen Callbacks), die Nonce-Behandlung in Formularen sowie Shortcode- und Block-Logik absichert und zwei Probleme des vorherigen Sicherheitsreleases bei post_status und anonymen Formular-Posts behebt.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 3.1.4.3: Umfassendes Sicherheitsupdate

Pods 3.1.4.3 ist ein umfassendes Sicherheitsupdate, das Display-Callbacks auf eine Allow-List sicherer Funktionen beschränkt (mit Admin-Hinweisen bei unzulässigen Callbacks), die Nonce-Behandlung in Formularen sowie Shortcode- und Block-Logik absichert und zwei Probleme des vorherigen Sicherheitsreleases bei post_status und anonymen Formular-Posts behebt.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 3.0.10.5: Umfassendes Sicherheitsupdate

Pods 3.0.10.5 ist ein umfassendes Sicherheitsupdate, das Display-Callbacks auf eine Allow-List sicherer Funktionen beschränkt (mit Admin-Hinweisen bei unzulässigen Callbacks), die Nonce-Behandlung in Formularen sowie Shortcode- und Block-Logik absichert und zwei Probleme des vorherigen Sicherheitsreleases bei post_status und anonymen Formular-Posts behebt.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 2.9.19.5: Umfassendes Sicherheitsupdate mit Callback-Allow-List

Pods 2.9.19.5 ist ein umfassendes Sicherheitsupdate, das Display-Callbacks auf eine Allow-List sicherer Funktionen beschränkt (mit Admin-Hinweisen bei unzulässigen Callbacks), die Nonce-Behandlung in Formularen sowie Shortcode- und Block-Logik absichert und zwei Probleme des vorherigen Sicherheitsreleases bei post_status und anonymen Formular-Posts behebt.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 2.8.23.5: Umfassendes Sicherheitsupdate mit Callback-Allow-List

Pods 2.8.23.5 ist ein umfassendes Sicherheitsupdate, das Display-Callbacks auf eine Allow-List sicherer Funktionen beschränkt (mit Admin-Hinweisen bei unzulässigen Callbacks), die Nonce-Behandlung in Formularen sowie Shortcode- und Block-Logik absichert und zwei Probleme des vorherigen Sicherheitsreleases bei post_status und anonymen Formular-Posts behebt.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 2.7.31.4: Umfassendes Sicherheitsupdate mit Callback-Allow-List

Pods 2.7.31.4 ist ein umfassendes Sicherheitsupdate, das Display-Callbacks auf eine Allow-List sicherer Funktionen beschränkt (mit Admin-Hinweisen bei unzulässigen Callbacks), die Nonce-Behandlung in Formularen sowie Shortcode- und Block-Logik absichert und zwei Probleme des vorherigen Sicherheitsreleases bei post_status und anonymen Formular-Posts behebt.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 3.3.9.1: Umfassendes Sicherheitsupdate empfohlen

Pods 3.3.9.1 ist ein umfassendes Sicherheitsupdate mit Härtungen bei Fehlerbehandlung, Datenabfragen, Anzeige und Verarbeitung von Werten, Datei- und Medien-Handling, Zugriffs- und Validierungsprüfungen, Admin-Formularen sowie Import-Inhalten, und ein baldiges Update wird empfohlen.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.

  • Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
  • Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
  • Security: Improved safety when handling previously stored data. (@sc0ttkclark)
  • Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
  • Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
  • Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Hardening improvements to file and media handling. (@sc0ttkclark)
  • Security: Additional safeguards for file and template handling. (@sc0ttkclark)
  • Security: Improved handling of displayed content. (@sc0ttkclark)
  • Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
  • Security: Additional validation for imported content. (@sc0ttkclark) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 3.2.8.3: Umfassendes Sicherheitsupdate empfohlen

Pods 3.2.8.3 ist ein umfassendes Sicherheitsupdate mit Härtungen bei Fehlerbehandlung, Datenabfragen, Anzeige und Verarbeitung von Werten, Datei- und Medien-Handling, Zugriffs- und Validierungsprüfungen, Admin-Formularen sowie Import-Inhalten, und ein baldiges Update wird empfohlen.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.

  • Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
  • Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
  • Security: Improved safety when handling previously stored data. (@sc0ttkclark)
  • Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
  • Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
  • Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Hardening improvements to file and media handling. (@sc0ttkclark)
  • Security: Additional safeguards for file and template handling. (@sc0ttkclark)
  • Security: Improved handling of displayed content. (@sc0ttkclark)
  • Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
  • Security: Additional validation for imported content. (@sc0ttkclark) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 3.1.4.2: Umfassendes Sicherheitsupdate empfohlen

Pods 3.1.4.2 ist ein umfassendes Sicherheitsupdate mit Härtungen bei Fehlerbehandlung, Datenabfragen, Anzeige und Verarbeitung von Werten, Datei- und Medien-Handling, Zugriffs- und Validierungsprüfungen, Admin-Formularen sowie Import-Inhalten, und ein baldiges Update wird empfohlen.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.

  • Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
  • Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
  • Security: Improved safety when handling previously stored data. (@sc0ttkclark)
  • Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
  • Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
  • Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Hardening improvements to file and media handling. (@sc0ttkclark)
  • Security: Additional safeguards for file and template handling. (@sc0ttkclark)
  • Security: Improved handling of displayed content. (@sc0ttkclark)
  • Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
  • Security: Additional validation for imported content. (@sc0ttkclark) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 3.0.10.4: Umfassendes Sicherheitsupdate empfohlen

Pods 3.0.10.4 ist ein umfassendes Sicherheitsupdate mit Härtungen bei Fehlerbehandlung, Datenabfragen, Anzeige und Verarbeitung von Werten, Datei- und Medien-Handling, Zugriffs- und Validierungsprüfungen, Admin-Formularen sowie Import-Inhalten, und ein baldiges Update wird empfohlen.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.

  • Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
  • Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
  • Security: Improved safety when handling previously stored data. (@sc0ttkclark)
  • Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
  • Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
  • Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Hardening improvements to file and media handling. (@sc0ttkclark)
  • Security: Additional safeguards for file and template handling. (@sc0ttkclark)
  • Security: Improved handling of displayed content. (@sc0ttkclark)
  • Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
  • Security: Additional validation for imported content. (@sc0ttkclark) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 2.9.19.4: Umfassendes Sicherheitsupdate empfohlen

Pods 2.9.19.4 ist ein umfassendes Sicherheitsupdate mit Härtungen bei Fehlerbehandlung, Datenabfragen, Anzeige und Verarbeitung von Werten, Datei- und Medien-Handling, Zugriffs- und Validierungsprüfungen, Admin-Formularen sowie Import-Inhalten, und ein baldiges Update wird empfohlen.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.

  • Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
  • Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
  • Security: Improved safety when handling previously stored data. (@sc0ttkclark)
  • Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
  • Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
  • Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Hardening improvements to file and media handling. (@sc0ttkclark)
  • Security: Additional safeguards for file and template handling. (@sc0ttkclark)
  • Security: Improved handling of displayed content. (@sc0ttkclark)
  • Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
  • Security: Additional validation for imported content. (@sc0ttkclark) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Pods von Pods Foundation

Pods 2.8.23.4: Umfassendes Sicherheitsupdate empfohlen

Pods 2.8.23.4 ist ein umfassendes Sicherheitsupdate mit Härtungen bei Fehlerbehandlung, Datenabfragen, Anzeige und Verarbeitung von Werten, Datei- und Medien-Handling, Zugriffs- und Validierungsprüfungen, Admin-Formularen sowie Import-Inhalten, und ein baldiges Update wird empfohlen.

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.

  • Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
  • Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
  • Security: Improved safety when handling previously stored data. (@sc0ttkclark)
  • Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
  • Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
  • Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Hardening improvements to file and media handling. (@sc0ttkclark)
  • Security: Additional safeguards for file and template handling. (@sc0ttkclark)
  • Security: Improved handling of displayed content. (@sc0ttkclark)
  • Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
  • Security: Additional validation for imported content. (@sc0ttkclark) …

Originalquelle(öffnet in neuem Tab)Problem melden