Release v3.3.0
WP Extended Pro v3.3.0
Latest versionWhat's new in v3.3.0
WP Extended Pro v3.3.0 was released on . WP Extended Pro is an all-in-one WordPress management plugin designed to streamline your website administration with an array of powerful features. See the full changelog below and compare with the complete version history.
Release details
Released
1.5 MB
File available
Changelog
Added
- Admin: Every module's settings now live under a single "WP Extended" screen, and moving between them no longer reloads the page.
- Translations: Now ships in German, Spanish, French, Dutch, Brazilian Portuguese and European Portuguese.
- Code Snippets: Added a Safe Mode switch to the editor, so you can turn every snippet off from the interface instead of by editing a URL.
Improved
- Limit Login Attempts: Added an option to trust a proxy header when detecting a visitor's IP address, for sites behind Cloudflare or a load balancer.
- Global: Updated module documentation links to our new documentation URLs.
- Menu Editor: A role granted a page now receives that page's capability only while WordPress is serving that page, not for the rest of the admin session. A delegated page that saves over the REST API or AJAX renders read-only.
- Global: Now requires a minimum of PHP 8.1.
Fixed
- Menu Editor: Fixed an issue where granting a role access to a page handed that role the page's capability everywhere in the admin, which could turn an Editor into a full administrator.
- Menu Editor: Fixed an issue where role restrictions had no effect on plugin pages, and where a denied page could still be reached through its object-edit URL.
- Menu Editor: Fixed an issue where saving without making a change reshuffled the admin menu.
- Media Replace: Fixed an issue where an Author could delete another user's attachments through the REST endpoint.
- Admin Columns: Fixed an issue where a custom meta column did not escape its value.
- Rollback Manager: Fixed an issue where version lists were fetched over an insecure connection.
- SVG Upload: Fixed an issue where the sanitiser could be bypassed by certain attributes and animation elements.
- Code Snippets: Fixed an issue where a snippet description could inject PHP into the generated file.
- Code Snippets: Fixed an issue where a snippet pasted with its own opening PHP tag could take the site down, and where updating, enabling and deleting failed on hosts that block PUT and DELETE requests.
- Admin Customiser: Fixed an issue where colour settings were not escaped on the login page.
- Limit Login Attempts: Fixed an issue where a spoofed IP address could bypass the lockout, or lock out every visitor behind a proxy.
- Limit Login Attempts: Fixed an issue where diagnostic REST routes were registered in production builds.
- Limit Login Attempts: Restored the unblock action, and fixed sorting and the status column.
- Settings: Fixed an issue where imported settings were saved without being sanitised or validated.
- Export Posts / Export Users / SMTP Email: Fixed an issue where CSV exports were not escaped against spreadsheet formula injection.
- Export Posts / Export Users: Fixed an issue where meta field exports returned blank values [Pro].
- User Switching: Fixed an issue where a favourited user's display name was not escaped in the admin bar.
- Folder Manager: Fixed an issue where a bulk move to a folder did not check permissions for each post.
- Folder Manager: Fixed an issue where a post duplicated from inside a folder was dropped out of it, and where sort links and status views kept the folder you had just left.
- User Enumeration: Fixed an issue where author requests were not blocked.
- Hide Author Slugs: Fixed an issue where author slugs were encrypted with a weak key.
- Hide Author Slugs: Fixed an issue where the Users screen crashed with a type error.
- Custom Login URL: Fixed an issue where the disabled-login message was not escaped and returned the wrong status code.
- Notices: Fixed an issue where notices could be read without logging in, and dismissed by any subscriber.
- Post ID Display: Fixed an issue where the module crashed when no post types were selected.
- Hide Admin Notices: Fixed an issue where the module crashed when nothing was selected for update notifications, and where update notices were not suppressed.
- Duplicate Posts & Pages: Fixed an issue where the module required Pro. It is free again, with its settings remaining Pro.
- Duplicate Post: Fixed an issue where duplicating an untitled post with content deselected returned an error instead of a clear message, and where editor scripts loaded on the Widgets screen.
- SMTP Email: Fixed an issue where a duplicate charset in the Content-Type header corrupted accented characters in some mail clients, and where the Download Logs button did nothing.
- WP-CLI: Fixed an issue where enabling a module that was already enabled turned it off.
- Post Type Switcher: Fixed an issue where every dropdown option was duplicated.
- Post Type Order: Fixed an issue where duplicate ordering was not always detected.
- Quick Add Post: Fixed an issue where the post-type restriction had no effect.
- Clean Profiles: Fixed an issue where the module did not hide anything.
- Fixed:
Compatibility
- Requires WordPress
- 5.6
- Tested up to
- 7.1
- Requires PHP
- 8.1
Verified safe
WP Extended Pro v3.3.0 scanned clean with no security threats detected.
View full scan report