You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@bahiirwa recently shared with me a link to the full changelog history for WC, with a view to going through to see if there is anything added in later versions that we may need to consider including or fixing in CC.
As I first step I have pulled out any line with the word "security". I am posting here to raise discussion about any security changes we feel may need to be addressed in CC. I have numbered the lines for easy reference.
@bahiirwa recently shared with me a link to the full changelog history for WC, with a view to going through to see if there is anything added in later versions that we may need to consider including or fixing in CC.
As I first step I have pulled out any line with the word "security". I am posting here to raise discussion about any security changes we feel may need to be addressed in CC. I have numbered the lines for easy reference.
ALREADY FIXED IN VERSION 1.0.4
Fix - Patched security vulnerability. https://woocommerce.com/posts/critical-vulnerability-detected-july-2021/
Others:
Security - Escape HTML in SelectWoo.* Security - Add an exit after the redirect when checking author archive capabilities for customers.* Security - Ensure 404 pages with single product urls cannot be exploited using Open Redirect.* Security - Introduce file type check for tax rate importer.* Security - Added nonce check to CSV importer actions.* Fix - Fix security check on email template preview page. #23356* Security - Added escaping for states on the user profile screen.Security - Added escaping for SelectWoo selected options.* Security - Improved the way in which state fields are regenerated by JavaScript to ensure values are properly escaped.Improved escaping for Photoswipe captions.Improved escaping for JSON attributes and structured data.The text was updated successfully, but these errors were encountered: