Security Fix:
- Cross-site scripting (XSS) vulnerability.
- A security researcher privately reported a bug about a cross-site scripting (XSS) vulnerability.
- Our team immediately took action, and provided the required patch within 2 hours, releasing the update on the same day after thorough validation.
- Users don’t need to panic. We haven’t heard of any exploit attempts using this vulnerability. However, we strongly recommend all our users to update Astra Pro as soon as possible.
- We take security very seriously and put in continuous efforts to keep our products safe, secure and reliable.
- Convert Pro version 1.4.2 has no known security vulnerabilities. And it is recommended that you update it now!
Improvement:
- Re-structured and optimized the codebase to improve security.
Fix:
- WP CLI support added.( https://www.convertpro.net/docs/wp-cli-commands/)
- Ultimate Addons for Visual Composer JS conflict – unable to edit the integrated mailer.
- Multiple info-bar overlapping on same position.
- Slide-in CTA position issue for toggle button on mobile and desktop in Editor.
- Slide-in CTA position issue with Multistep for toggle button on mobile and desktop in Editor.
- Slide in CTA position ‘bottom centre’ issue with toggle button on desktop.
- Slide-in CTA with sticky toggle not working on mobile.