Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
105abf4e24 | ||
|
|
d48beb9757 | ||
|
|
4a43572b15 | ||
|
|
20c46d3d26 | ||
|
|
74fdd42561 | ||
|
|
1e4806457e | ||
|
|
da9237171a | ||
|
|
904bf52960 | ||
|
|
8ea7b9f5be | ||
|
|
804a1aae58 | ||
|
|
76e585139e | ||
|
|
f871592d27 | ||
|
|
f1375d3d7d | ||
|
|
72fa8e8901 | ||
|
|
efa84723ee | ||
|
|
39616478c9 | ||
|
|
c1969d4293 | ||
|
|
524b893e65 | ||
|
|
303f31e869 | ||
|
|
20a2a84ee8 | ||
|
|
9127b06836 | ||
|
|
19cb788556 | ||
|
|
e52046437b |
+7
-7
@@ -1,11 +1,11 @@
|
||||
{
|
||||
"version": "7.23.14",
|
||||
"released_at": "2026-08-10T10:42:30+00:00",
|
||||
"package_url": "https://git-cloud.weboria.eu/Weboria/argus-wp-defence/releases/download/v7.23.14/argus-wordpress-defence-7.23.14.zip",
|
||||
"sha256": "6b2365b173bd8e583a5d04021d205c773f927217b4870fc3ebff8c298c53367b",
|
||||
"version": "7.23.38",
|
||||
"released_at": "2026-08-12T17:08:27+00:00",
|
||||
"package_url": "https://git-cloud.weboria.eu/Weboria/argus-wp-defence/releases/download/v7.23.38/argus-wordpress-defence-7.23.38.zip",
|
||||
"sha256": "ca6d9a05d749f2483089bd2f6b9f58b322384f51a39c29fd90bb339c5bfc397f",
|
||||
"min_php": "7.4",
|
||||
"min_wp": "6.0",
|
||||
"critical": true,
|
||||
"summary": "* Fixed a serious bug: the Firewall could block ordinary visitors just for arriving from an\n everyday link -- for example, a link shared on Facebook, whose own redirect URL happened to\n match a pattern the Firewall treated as suspicious. The underlying cause was broader than that\n one case: 132 of the Firewall's 137 protection rules were checking a visitor's Referer,\n User-Agent, and X-Forwarded-For information -- values a visitor doesn't control -- when they\n should only ever have been checking what a visitor actually submits (search terms, form fields,\n comments, and similar). Those three values are now excluded everywhere except the handful of\n rules that specifically need them (Log4Shell-style attacks are delivered through exactly those\n values, so detection there is unchanged). No settings change needed; this takes effect\n automatically.",
|
||||
"signature": "l3gHdqDlNbkuk88XuJpVOMiAbAMNVoht7lVJ0UgkgvcLgDUTmcnaYS9g6XoHqH6sPTkmLA6TL2SYe3d2d1NOCA=="
|
||||
"critical": false,
|
||||
"summary": "* Findings that ARGUS already handled automatically (a blocked WAF request, a blocked file\n upload, blocked REST user-enumeration probing) no longer sit in \"Needs Attention\" -- the same\n fix already shipped for brute-force login findings in 7.23.37 now covers every place this\n happened. Existing findings from before this fix are cleaned up automatically on update, not\n just new ones going forward.\n* The Protection Score on Overview is now color-coded (green/yellow/orange/red) instead of always\n the same color regardless of how healthy your site actually is.\n* Backup integrity is now fully automatic end to end -- no \"Verify\" button to click; ARGUS\n re-checks every backup's integrity once a day on its own, on top of the check it already does\n the moment a backup is created.\n* The Backups page now displays properly on a phone.\n* New \"Purge Audit Log\" option on the Audit Log page, for clearing it manually at any time.",
|
||||
"signature": "y9yWsjrUnm9datO0rsvoQRudPDAtG3e7fpnCjuPNWr33nTsz1js9l0PXiCer7otHeaL6QyDSV+Q0j+R6xZBhCQ=="
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user