403Webshell
Server IP : 104.26.4.103  /  Your IP : 216.73.217.51
Web Server : nginx/1.27.1
System : Linux in-5 5.15.0-191-generic #201-Ubuntu SMP Fri Aug 7 18:39:04 UTC 2026 x86_64
User : arabianexpress ( 1872)
PHP Version : 8.0.30
Disable Function : exec,passthru,shell_exec,system,proc_open,popen,parse_ini_file,show_source
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /storage/v9321/buzzbitesv3/public_html/wp-content/plugins/migrator-plugin-1.1.0/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /storage/v9321/buzzbitesv3/public_html/wp-content/plugins/migrator-plugin-1.1.0/changelog.txt
Changelog
=========

All notable changes to the Hostinger Migrator plugin are documented in this file.
Versions before 1.1.0 predate this changelog and are not listed.


1.1.0 - 2026-09-18
------------------

Security release. Upgrading is strongly recommended for every install.

Security

* Removed the wp_ajax_nopriv registrations for "cm_fallback_export" and
  "cm_fallback_status". Both handlers ran a full database and file export and
  were reachable by unauthenticated visitors. They now require the
  manage_options capability and a valid nonce, checked before any filesystem
  work is performed.
* The database export no longer accepts a "temp_file_path" parameter from the
  request. On resume, the temp file name is recovered from server-side state
  and the directory is derived from the generated SQL file path, so the SQL
  dump can no longer be steered to an arbitrary web-server-writable location.
  A final check rejects any resolved path outside the export directory or with
  an unexpected file name.
* Removed the "background_mode" authentication bypass in "cm_run_export_now".
  The flag was a plain request parameter, so any logged-in user could use it to
  skip the capability and nonce checks and start a full export. Background
  execution continues through the cm_run_export cron hook.
* Gave "cm_process_export_step" a dedicated AJAX entry point with capability
  and nonce checks. The underlying method no longer merges $_GET/$_POST into
  its parameters and is now internal only.
* Added the missing nonce check to plugin deletion ("cm_delete_plugin"), which
  was CSRF-able into deleting the plugin and all export data.
* Added a capability check to "cm_get_export_status_display" and
  "cm_get_s3_status_display", which previously exposed migration status to any
  logged-in user.
* Sanitized the fallback export session id, which was taken from the request
  unfiltered and written to the lock file and log.

Changed

* The export directory .htaccess is now default-deny with an allow list limited
  to the randomly named export artifacts. Status, step, lock, content-list and
  temporary SQL files are no longer served. The rules emit both Apache 2.2 and
  2.4 authorization syntax so they neither silently no-op nor fail depending on
  which authz module is loaded, and PHP execution is disabled for the
  directory.
* The export directory guard files (.htaccess, index.php) are now (re)written
  whenever they are missing or out of date, instead of only when the directory
  is first created. Existing installs are healed on the next admin page load.
* All code paths that create the export directory now go through
  Custom_Migrator_Filesystem::create_export_dir(). The fallback exporter and
  the database exporter previously created it with a bare wp_mkdir_p(), which
  produced a directory with no access protection at all.

Fixed

* The plugin header version (1.0) and CUSTOM_MIGRATOR_VERSION constant (1.0.0)
  no longer disagree.

Notes for hosting environments

* The export directory protection relies on .htaccess, which Apache and
  LiteSpeed honour but nginx ignores. On nginx the export artifacts are
  protected only by the random component of their file names. Serving
  downloads through an authenticated endpoint is tracked as follow-up work.

Upgrade notes

* Any external automation that called "cm_fallback_export",
  "cm_fallback_status", "cm_run_export_now" or "cm_process_export_step" without
  an authenticated session will stop working. These endpoints now require an
  administrator session and a "custom_migrator_nonce" nonce.
* Adds the "custom_migrator_db_temp_file" option, which holds the active
  database export temp file name. It is cleared when an export finishes and
  removed on uninstall.

Youez - 2016 - github.com/yon3zu
LinuXploit