= 8.5
Fixed missing current_user_can() check on 7 AJAX handlers (unauthorized data access)
Fixed unauthenticated DROP TABLE via ?action=fixed_db_issue — added capability check + nonce (CVE-2025-49996)
Added wp_nonce_url() to both “Fix now!” buttons
Fixed Stored XSS in wsm_showDayStatsGraph shortcode — sanitized all user-supplied attributes before output
= 8.4
Security: Fixed stored XSS in wsm_showLastDaysStatsChart shortcode by sanitizing data before output.
= 8.3
Security: Fixed stored XSS in wsm_showMostActiveVisitorsGeo shortcode by sanitizing zoom, id, and height attributes before output.
Updated the data type of some database columns to fix the Out of range value for column ‘id’
Updated the data type of the id column from TINYINT(2) UNSIGNED to INT UNSIGNED to support more than 255 records per table.
Bug Fixing: vulnerable to Cross Site Scripting (XSS)
Nonce check, IP validation, security improvements
Exclude both IPv4 and IPv6.
Security bug fixing
Enhancing plugin security by fixing existing vulnerabilities and implementing additional security measures.
Security bug fixing
Bug fixing – customizer issue
Bug fixing when giving access to the editor users
Plugin Website
Visit website
Share Post
Get insights into what’s happening at ChangelogWP right in your inbox. We don’t believe in spam.