All-In-One Security Premium Release 1.0.4 Release
The latest release from AIOS includes a new IP lookup function that will help developers identify suspicious activity such as password resets.
New IP lookup function
Section titled New IP lookup functionOur new IP lookup function informs web owners of the IP address of anyone who tries to reset your password, or lockdown your site. If that happens, you’ll receive an immediate email containing this crucial security information. This will help you identify any suspicious or potentially malicious activity. For example, if the IP address comes from an unrecognised country, it’s likely fraudulent.
Security fixes
Section titled Security fixesThe release also includes a security fix to remove unnecessary uses of the tab query parameter on various admin menu pages. This helps to prevent cross-site scripting vulnerabilities. Cross site scripting allows malicious users to inject unwanted scripts into your website, in this case through the AIOS admin page. Thank you to Matthew Rollings for disclosing the vulnerability.
Premium release 1.0.4 also contains a number of smaller tweaks and fixes, full details of which can be found below.
Changelog
Section titled Changelog- SECURITY: Removed unnecessary use of the
tabquery parameter on various admin menu pages to prevent a XSS vulnerability. Thanks to Matthew Rollings for disclosing this defect. - FEATURE: Added Reverse IP Lookup location data to login lockdown notification email
- Feature: Enhance reset password email by adding IP info
- Fix: A fatal error on PHP 8.0+ when you have premium active but not the free version
- Fix: Smart 404 blocking does not work if time zone other than UTC set.
- Tweak: Various tweaks to get codebase up to coding standards
- Tweak: Removed some unused files
About the author
TeamUpdraft
Our team consists of WordPress developers, marketers, and industry experts committed to providing you with the resources and skills you need to succeed online. Whether you’re just starting out or seeking advanced strategies, we’re here to enhance your WordPress journey and support you at every stage.
Categories
AIOS
Comprehensive, feature-rich, security for WordPress. Malware scanning, firewall, an audit log and much more. Powerful, trusted and easy to use.
From just $70 for the year.
More stories
-
UpdraftPlus releases v1.24.7 and v2.24.7
UpdraftClone now supports PHP 8.4—test your WordPress site before upgrading. Don’t risk breaking your site; try UpdraftClone today!
-
All-In-One Security release v5.3.4
All-In-One Security 5.3.4 adds HTTP auth for WordPress dashboard, enhancing protection against brute-force attacks.
-
All-In-One Security release v5.3.3
All-In-One Security 5.3.3 introduces CAPTCHA for WooCommerce guest checkout, reducing fraudulent orders and enhancing bot protection.
-
WP-Optimize release v3.7.0
WP-Optimize 3.7.0 introduces automatic content preloading and plugin performance detection to boost your site’s speed and efficiency.