8.0.3

2023-10-30 Security1 Tweak4 Fix5

Security

  • Don't disclose the login URL when using Hide Backend on a site with comments enabled and comment registration required. Thanks to Naveen Muthusamy for disclosing this issue.

Tweaks

  • Check for the promote_user capability when using Privilege Escalation in addition to edit_user.
  • Remove the iThemes Security is now Solid Security banner from admin-facing email notifications.
  • The lib/updater library has been updated to 1.8.1
  • Add a wp ithemes-licensing set-licensed-url WP-CLI command.

Fixes

  • Prevent the User Security page from crashing when "Show Avatars" is disabled in the WordPress discussion settings.
  • Fix some filters on the User Security page not working as expected.
  • Fix spacing on the Two-Factor form when backup methods are enabled.
  • Fix fatal error when there is an error retrieving Patchstack license information.
  • Styling issues on WordPress 6.4.