Fix: Prevented bundled sodium_compat library from conflicting with versions included with older WordPress versions
* Improvement: Added support for processing arrays of files in the WAF
* Improvement: Refactored security event processing to send events in bulk
* Improvement: Updated bundled sodium_compat and random_compat libraries
* Fix: Prevented deprecation warning caused by dynamic property creation
* Fix: Added translation support for additional strings
* Change: Adjusted Wordfence registration UI
- Improvement: Added translation support for strings from login security plugin
- Improvement: Added translator notes regarding word order and hidden text
- Improvement: Added translation support for additional strings
- Improvement: Prevented scans from failing if unreadable directories are encountered
- Improvement: Added help link to IPv4 scan option
- Improvement: Updated scan result text to clarify meaning of plugins removed from wordpress.org
- Improvement: Made “Increased Attack Rate” emails actionable
- Improvement: Updated GeoIP database
- Improvement: Updated JavaScript libraries
- Fix: Corrected IPv6 address expansion
- Fix: Ensured long request payloads for malicious requests are recorded in live traffic
- Fix: Prevented “commands out of sync” database error messages when the database connection has failed
- Fix: Prevented rare JSON encoding issues from breaking free license registration
- Fix: Prevented PHP notice from being logged when request parameter is missing
- Fix: Prevented deprecation warning in PHP 8.1
- Change: Moved detection for old TimThumb files to malware signature
- Change: Moved translation file from .po to .pot
- Change: Renamed “Macedonia” to “North Macedonia, Republic of”
- Improvement: Added exception handling to prevent WAF errors from being fatal
- Fix: Corrected error caused by method call on null in WAF
- Change: Deprecated support for PHP 5.5 and 5.6, ended support for PHP 5.3 and 5.4
- Change: Specified WAF version parameter when requesting firewall rules
- Improvement: The vulnerability severity score (CVSS) is now shown with any vulnerability findings from the scanner
- Improvement: Changed several links during initial setup to open in a new window/tab so it doesn’t interrupt installation
- Change: Removed the non-https callback test to the Wordfence servers
- Fix: Fixed an error on PHP 8 that could occur when checking for plugin updates and another plugin has a broken hook
- Fix: Added a check for disabled functions when generating support diagnostics to avoid an error on PHP 8
- Fix: Prevent double-clicking when activating 2FA to avoid an “already set up” error
- Fix: Prevented scan resume attempts from repeating indefinitely when the initial scan stage fails
- Improvement: Added configurable scan resume functionality to prevent scan failures on sites with intermittent connectivity issues
- Improvement: Added new scan result for vulnerabilities found in plugins that do not have patched versions available via WordPress.org
- Improvement: Implemented stand-alone MMDB reader for IP address lookups to prevent plugin conflicts and support additional PHP versions
- Improvement: Added option to disable looking up IP address locations via the Wordfence API
- Improvement: Prevented successful logins from resetting brute force counters
- Improvement: Clarified IPv6 diagnostic
- Improvement: Included maximum number of days in live traffic option text
- Fix: Made timezones consistent on firewall page
- Fix: Added “Use only IPv4 to start scans” option to search
- Fix: Prevented deprecation notices on PHP 8.1 when emailing the activity log
- Fix: Prevented warning on PHP 8 related to process owner diagnostic
- Fix: Prevented PHP Code Sniffer false positive related to T_BAD_CHARACTER
- Fix: Removed unsupported beta feed option
* Improvement: Hardened 2FA login flow to reduce exposure in cases where an attacker is able to obtain privileged information from the database
= 7.6.1 - September 6, 2022 =
* Fix: Prevented XSS that would have required admin privileges to exploit (CVE-2022-3144)
Download Wordfence v7.6.0 - WordPress Security Plugin Nulled Free
= v7.6.0 - July 28, 2022 =
* Improvement: Added option to start scans using only IPv4
* Improvement: Added diagnostic for internal IPv6 connectivity to site
* Improvement: Added AUTOMATIC_UPDATER_DISABLED diagnostic
* Improvement: Updated password strength check
* Improvement: Added support for scanning plugin/theme files in when using the WP_CONTENT_DIR/WP_PLUGIN_DIR constants
* Improvement: Updated GeoIP database
* Improvement: Made DISABLE_WP_CRON diagnostic more clear
* Improvement: Added "Hostname" to Live Traffic message displayed for hostname blocking
* Improvement: Improved compatibility with Flywheel hosting
* Improvement: Adopted semantic versioning
* Improvement: Added support for dynamic cookie redaction patterns when logging requests
* Fix: Prevented scanned paths from being displayed as skipped in rare cases
* Fix: Corrected indexed files count in scan messages
* Fix: Prevented overlapping AJAX requests when viewing Live Traffic on slower servers
* Fix: Corrected WP_DEBUG_DISPLAY diagnostic
* Fix: Prevented extraneous warnings caused by DNS resolution failures
* Fix: Corrected display issue with Save/Cancel buttons on All Options page
* Fix: Prevented errors caused by WHOIS searches for invalid values