Newsletters 4.14 Release Notes
-Release notes for version 4.14 of the WordPress Newsletter plugin.
This is a small update. We are preparing a larger v5.0 update with new features and improvements. Coming soon!
Improved
- Serial key modal messaging and redirects after entering valid, expired, or deleted serial keys.
Fixed
- Expired but valid serial keys can continue using PRO features such as the Drag & Drop Builder, premium CAPTCHA options, and resend/manage subscription links.
- Expired serial key messaging no longer sends paid users to an empty upgrade page.
- Serial key validation now uses the latest online validation result immediately after entering or deleting a key.
- Broken Access Control vulnerability in deleteuser function. Added CSRF nonce check and fixed inverted authorization logic. Prevented administrators from deleting their own accounts.
- SQL injection vulnerability in newsletters_management shortcode via wpmlsubscriber_id parameter. Implemented $wpdb->prepare() for parameterized queries.
- SQL injection vulnerability in history email resend function. Implemented $wpdb->prepare() for parameterized queries.
- SQL injection vulnerability in queue processing function. Implemented $wpdb->prepare() for parameterized queries.
- SQL injection vulnerability in mailing list activation handler. Implemented $wpdb->prepare() for parameterized queries.
Website & Email Hosting
Get the best website & email hosting for speed, security, and peace of mind. No restrictions. Freedom to do what you need in order to run your business.
