8.4.1
2024-03-21 Security1 Deprecated1 Tweak3 Fix2Security
- Fix a Google reCAPTCHA v3 bypass.
Deprecateds
- "Automatic (Insecure)" IP detection has been removed. Read more: https://go.solidwp.com/firewall-features-not-available
Tweaks
- Block repeated session hijacking attacks from the same device even if the user has not specifically blocked the attacker's device. Previously, subsequent attacks after the first block would have their capabilities reduced.
- Remove the "Accept-Language" and "DNT" header from the list of sources for Trusted Devices.
- The Updater library has been updated to 1.8.4. The list of Patchstack licensed domains have been removed from the SolidWP licensing page.
Fixes
- Fix the Trusted Devices "Approve" link in Outlook mail clients.
- The "Privilege Escalation" tab would not appear in a user's profile unless Passwordless Login was enabled.
