Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-11738: Duplicator Changelog History – Snap Creek Software

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via …/ in the file parameter to duplicator_download or duplicator_init.

CVE
#sql#csrf#web#ios#mac#google#amazon#apache#js#java#wordpress#php#perl#auth#sap#ssl

**4.5.7 **Latest-Stable****

Release Date: 2022-9-19
PHP Version: 5.6.20+

WordPress Version: 4.0 or greater
Tested up to: 6.0.2

Overview:
The 4.5.7 release contains several small fixes and updates.

View All 4.5.7 Changes

PLUGIN
[UPD]: Updated the message in case of removed recovery point
[UPD]: Improved error detection during setting recovery point
[UPD]: Improved checking of required functions and classes in requirements section, just before package creation
[UPD]: Updated the German translation
[UPD]: Fixed template save button being disabled
[FIX]: Miscellaneous internal fixes and improvements
[FIX]: Fixed the local storage export file warnings due to a missing SQL file

INSTALLER
[NEW] Added new validation test called “PHP Functions and Classes”
[FIX]: Miscellaneous internal fixes and improvements

4.5.6

Release Date: 2022-8-30
PHP Version: 5.6.20+

WordPress Version: 4.0 or greater
Tested up to: 6.0.1

Overview:
The 4.5.6 release contains quite a few fixes and updates as well as a couple of new small features.

View All 4.5.6 Changes

PLUGIN
[NEW]: Enhanced the imported package information under package details
[UPD]: Fixed invalid state error when wrong auth code is entered for OneDrive
[UPD]: Update Tippy to latest version and refactor tooltip related event handlers that were reported as deprecated by jQuery Migrator.
[UPD]: Removing old constant DUP_SECURE_KEY from wp-config if new one is prepared/exists.
[UPD]: Added a quick fix to remove installer files when scheduled build fails
[UPD]: Updated api client for Google Drive, since Google will no longer support the “out of band” flow.
[UPD]: Removed the usage of shell_exec and instead using exec.
[FIX]: Added checks to prevent creating local storages inside core WordPress directories.
[FIX]: Added checks to prevent creating more than one local storage in the same folder.
[FIX]: Exception class name is displayed in the “test s3connection” dialog for S3 remote storage configuration.
[FIX]: Skip disk checks if PHP disk functions are not available
[FIX]: Compatibility with Google Cloud in S3 mode fixed
[FIX]: Fixed OneDrive notices that were appearing after authorization of personal OneDrive storage.
[FIX]: Clearing the output buffers before ending the buffering output
[FIX]: fixed timezone and server time strings in the “Tools” screen
[FIX]: Now possible to create multiple Google Drive storages for the same account

INSTALLER
[NEW]: Now importing a site to a multisite also handles installations with multiple domains
[UPD]: Removed the usage of shell_exec and instead using exec.
[FIX]: Fixed bug related to upload url not being correctly replaced in some cases when doing a subsite standalone install with SSL enabled
[FIX]: Clearing the output buffers before ending the buffering output

**4.5.5.2 Patch **

Release Date: 2022-7-31
PHP Version: 5.6.20+

WordPress Version: 4.0 or greater
Tested up to: 6.0.1

PLUGIN
[FIX]: Fixed bugs related to SFTP transfers that were introduced in v4.5.5

**4.5.5.1 Patch **

Release Date: 2022-7-24
PHP Version: 5.6.20+

WordPress Version: 4.0 or greater
Tested up to: 6.0.1

PLUGIN
[FIX]: Fixed blank screen after exceeding max build time

4.5.5

Release Date: 2022-7-18
PHP Version: 5.6.20+

WordPress Version: 4.0 or greater
Tested up to: 6.0.1

Overview:
The 4.5.5 release contains quite a few fixes and updates as well as a couple of new small features.

View All 4.5.5 Changes

PLUGIN
[NEW]: Split and adapted form tables for 3 different kinds of S3 providers, including one specialized for Backblaze.
[UPD]: Improve recovery point UI with help icons
[UPD]: Added a feature to remove unused plugins and themes
[UPD]: Improved handling of installer file name and filters applied to it in the code
[UPD]: Removed usage of DUP_PRO_RestoreOnly_Package class
[UPD]: Improve scanner message for mixed-case DB tables names
[UPD]: Improved scheduled build email with additional information about the package
[UPD]: “Save Brand” button disabled except when it is needed.
[UPD]: Disable notice that recommends Duparchive on a new site
[UPD]: Exposed real region values in UI for Amazon S3 Direct storage, next to the human readable strings
[UPD]: Added a specific error message for cases where the archive package file is missing
[UPD]: Updated phpseclib to the latest version
[UPD]: Make multisite tab (build step 1) visible for all license types, but only enabled for Business and Gold
[UPD]: The tmp folder will be emptied every 24 hours
[FIX]: Eliminated image overflow problem in branding preview
[FIX]: Fixed strings referring to Amazon S3

INSTALLER
[NEW]: Added a feature to remove users without permissions
[UPD] Showing correct message on AJAX error with status code and appropriate documentation link
[UPD]: Improved the Cleanup Labels in the Advanced Installer
[UPD]: Added an explanation to help for the Cleanup options
[UPD]: Prevent click of browser backward and forward buttons
[UPD]: Introduced a new archive check for manual extracts
[UPD]: Encapsulated the check for manual extracts case and installation directory existence
[FIX]: Fixed invalid charset and collate replace bug
[FIX]: Fixed the missing getSuperAdminsUserIds method in DUPX_MU
[FIX]: Create new tables option not to trigger the count of affected tables
[FIX]: Fixed a bug that was preventing the installer to work if “Create Database” is selected in the first step

4.5.4

Release Date: 2022-6-14
PHP Version: 5.6.20+

WordPress Version: 4.0 or greater
Tested up to: 6.0.0

Overview:
The 4.5.4 release is a cumulative bug fix version, no new features have been added in this release.

View All 4.5.4 Changes

PLUGIN
[UPD]: Storage keys/pass for S3/FTP/SFTP are not rendered in HTML, the values to be retained on the server
[UPD]: Make link to FAQ for Max Build Time quick fix open in new window
[UPD]: Updated Save button for Schedules, Storages and Templates to be disabled by default
[UPD]: Improved feedback messages for “Test S3 Connection” so users can identify connection problems more accurately
[UPD]: Enhanced mysqldump error message
[FIX]: Improved Multisite message for package scan at “Personal” license level
[FIX]: Fixed an issue with symbolic link inserted in a local storage and not automatically filtered when creating the package
[FIX]: Fixed timeout problem on same servers for import/recovery package prepare
[FIX]: Fixed a problem in the rename of the installer.php file after installation
[FIX]: Eliminated image overflow problem in branding preview
[FIX]: Tables with no WP prefix are correctly filtered when the filter is set in a template
[FIX]: DupArchive compression setting is not switched on automatically anymore with PHP < 7.0

INSTALLER
[UPD]: Improved GTID mode detection in installer validation
[UPD]: Improved performance on AddonSites search
[UPD]: Improve the installer database action names in step 1
[FIX]: Fixed path handling in case of modifying ABSPATH starting from a site with standard configuration
[FIX]: Add a check to prevent trying to delete the duplicator_pro_packages table if it was filtered out from the archive

**4.5.3.2 Patch **

Release Date: 2022-6-8
PHP Version: 5.6.20 or higher

WordPress Version: 4.0 or greater
Tested up to: 6.0

PLUGIN
[FIX] Removed clearing of update_plugins transient since occasionally caused problems with other plugins/themes
[FIX] Better error handling when .htaccess not permitted to be created
[FIX] Addressed problem when migrating NinjaForms

**4.5.3.1 Patch **

Release Date: 2022-5-29
PHP Version: 5.6.20 or higher

WordPress Version: 4.0 or greater
Tested up to: 6.0

PLUGIN
[UPD]: Update tested version and core file list to WordPress 6.0
[FIX]: Fixed a problem in package creation in case the root path is /
[FIX]: Fixed an error in case the phpinfo function is disabled

4.5.3

Release Date: 2022-5-23
PHP Version: 5.6.20+

WordPress Version: 4.0 or greater
Tested up to: 5.9.3

Overview:
The 4.5.3 release is a cumulative bug fix version, but also comes with some exciting new features. The first is the highly requested feature around archive encryption. The archive.zip/daf file can now be encrypted with a password. This new feature will help users add additional security to their archive files. Additionally the Duplicator Pro plugin can be set to auto-update when a new version is released.

View All 4.5.3 Changes

PLUGIN
Plugin [NEW]: Archive password encryption, improved support for AES-256 encryption on the archive.zip/daf file
Plugin [NEW]: Auto updates for the plugin are now available Updated EDD_SL_Plugin_Updater to version 1.9.1
Plugin [NEW]: Added functionality to download packages saved at non-default local storage from the front-end
Plugin [NEW]: Added link for downloading the installer file in the “Package File Links” dialog box in the package’s details page
Plugin [NEW]: Added automated installer cleanup options in Settings ❯ Packages Tab ❯ Cleanup Modes (Email Notice and Auto Cleanup)
Plugin [UPD]: Minimum version required PHP 5.6.20
Plugin [UPD]: Removed the old CRON library and setting so that the schedule library only uses the new one
Plugin [UPD]: Improve the content and layout of the Duplicator Pro Tutorial
Plugin [UPD]: Update the Templates and edit UI to be closely correlated to the create package UI
Plugin [UPD]: Improved import fail message
Plugin [UPD]: Updated Duplicator Pro define auth key name
Plugin [FIX]: Improved time zone handling for scheduled builds
Plugin [FIX]: Eliminated image overflow problem in branding preview
Plugin [FIX]: Fixed a problem with reading the list of MySQL enabled engines
Plugin [FIX]: Improved storage information handling
Plugin [FIX]: Fixed error on WP-CLI plugin activation
Plugin [FIX]: Fixed a problem in the creation of the package with the mysqldump in some configurations of the DBHOST
Plugin [FIX]: Installer can be downloaded and package transferred when the package is created on WPEngine or Cloudways hosting
INSTALLER
Installer [NEW]: Archive password encryption
Installer [FIX]: Fixed problem of interference of .htaccess from dup-installer folder with the installer
Installer [FIX]: Fixed toggle password on the new admin password field

4.5.2

Release Date: 2022-4-19
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.9.3

Overview:
The 4.5.2 is a cumulative bug fix version. Many small/medium sized bug fixes have been added to improve stability. The Duplicator Pro plugin now allows for developers to hook into certain events that happen during its execution cycles. Below is an overview of the currently supported hooks.

View All 4.5.2 Changes

PLUGIN
[NEW]: Plugin Hooks now available for developers.
[NEW]: Added option to automatically filter files with invalid encoded names
[UPD]: Improved form to use relative URLs in action
[UPD]: Minor installer UI improvement including improving the tutorial
[UPD]: Removed SSL Verify setting from the Settings ❯ Packages ❯ Advanced UI
[FIX]: Fixed wp-content quick link in templates
[FIX]: Fixed wrong calculation of time for scheduled backups related to Daylight Saving Time
[FIX]: Fixed problem with Backblaze related to object-level ACLs
[FIX]: Fixed bug related to having multiple creation queries for MySQL Procedures and Functions
[FIX]: Fixed an issue in the DupArchive that occasionally caused validation to fail
[FIX]: Fixed bug in Cron expression library that prevented a schedule from saving when: Monthly (any day) of every 12 months was set
[FIX]: Improve wording on Step 1 filters
INSTALLER
Installer [NEW]: Added option to set SQL connection flags in wp-config

4.5.1

Release Date: 2022-3-15
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.9.3

Overview:
The 4.5.1 is a cumulative bug fix version. Many small/medium sized bug fixes have been added to improve stability and improve some of edge case scenarios. Additional improvements to some of the user interfaces include better support for FTP/credential feedback and the installer database validation dialog along with better support for Bitnami stacks.

View All 4.5.1 Changes

PLUGIN
[NEW]: Encryption key is now stored in wp-config.php instead of dynamically determined
[UPD]: The Cron Expression is now the recommended and default parser
[UPD]: Improved UI dialog for FTP/SFTP connection tests and overall feedback and status
[FIX]: Show single quick fix when build time exceeds max build time
[FIX]: Fixed a problem in the creation of the package when the wp-config was in the parent folder in spite of ABSPATH
INSTALLER
[NEW]: Improve Bitnami support
[UPD]: In case the wp-config does not have write permissions the wordpress prefix is updated correctly
[UPD]: Improved validation test for new table names that exceed 64 chars, for cases when importing site(s) into multisite
[UPD]: Improve the database confirmation dialog to show for an empty database
[FIX]: Removed the htaccess from the dup-installer folder that could cause problems in some cases

4.5.0

Release Date: 2022-2-21
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.8.3

Overview:
The 4.5.0 release adds direct import of packages into destination site using URL (server-to-server transfer). Additionally, v4.5.0 includes many smaller improvements including UI tweaks and logic cleanup.

View All 4.5.0 Changes

PLUGIN
[NEW]: Import package with URL. Allows server-to-server package transfer - No need to download a package to your desktop machine!
[NEW]: Server-to-server Dropbox import support added
[NEW]: Added a new option that allows you to set a custom path for importable packages
[NEW]: Improved UX when storages associated with schedules are deleted
[NEW]: Added bulk activate and deactivate options for schedules
[NEW]: Manual transfer screen updated to include quick copy links for hashed files
[UPD]: disable S3 storage if any curl_multi_* function is disabled
[FIX]: Not showing the activation notice for plugins which are already activated once
[FIX]: Fixed bug related to the basic auth quick fix notification not being displayed
[FIX]: fixed filter_var bug with PHP versions less than v5.4.8
[FIX]: Validation performed on filters only in case when they are ON
INSTALLER
[NEW]: Added validation message notifying the user about having multiple WP installations on the same database
[NEW]: Added support for SSL connections to remote mysql servers
[NEW]: Check if index.html exists on destination site and, if it does, displays a warning in the final report
[UPD]: Reorganized database parameters in advanced mode
[UPD]: Removed non-braking spaces option
[UPD]: In “Backup and Rename Existing Tables” action, if limit of 64 chars in table name is exceeded, made sure that new table name is unique
[NEW]: Added new validation test in ‘Classic install’ which tests if limit of 64 chars in table name is exceeded by adding prefix
[FIX]: Fixed bug where paths with no write permission are not being displayed
[FIX]: Fixed timeout error that was happening on some hosts when exec command hangs
[FIX]: fixed PROCS, VIEWS and FUNCTIONS creation bug for older versions of PHP
[FIX]: Copy Recovery URL button now works in import installer

**4.0.6.2 Patch **

Release Date: 2022-2-4
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.9

PLUGIN
[FIX]: Fixed problem that prevented sites with expired certificates from importing.
INSTALLER
[FIX]: Fixed problem with serialized objects getting corrupted when they had non-breaking spaces between strings.

**4.0.6.1 Patch **

Release Date: 2022-2-1
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.9

PLUGIN
[FIX]: Fixed SFTP data storage
[FIX]: Enhanced import logic to account for case when hosting prevents PHP files from being executed inside wp-content
[FIX]: Added preliminary check when setting up the Recovery Point to make sure recovery is possible.

4.0.6

Release Date: 2022-1-10
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.8.3

Overview:
The 4.0.6 release adds bulk imports of subsites into multisite networks. Additionally, v4.0.6 includes many small improvements including UI tweaks and logic cleanup.

View All 4.0.6 Changes

PLUGIN
[NEW]: Added option that allows to exclude all tables that do not have the prefix of the current wordpress installation
[NEW]: Added option that allows to exclude all tables that belong to deleted sites in a multisite installation
[NEW]: Bulk subsite import in multisite
[UPD]: Updated error messages that appears if a user tries to activate Duplicator Pro plugin while Lite version is active
[UPD]: Symlinks for main WordPress folders (wp-content, plugins …) managed as normal folders in case they are children of home path
[UPD]: Added schedule name to scheduled package built emails
[UPD]: Improved the accessibility of the packages screen and the overall build process
[UPD]: Writing better description in log when installer files present during (scheduled) build
[FIX]: Now backup-dup-pro folder is correctly filtered automatically even if wp-content is a symlink
[FIX]: Safe mode docs and settings are now properly set to Enabled/Disabled
[FIX]: Removed unnecessary check in EDD client
[FIX]: Third party backup folders are again filtered and not included in packages by default
[FIX]: Fixed bug in the startup of the Drag and Drop installation that in some rare cases was not executed correctly
[FIX]: Fixed recovery point bug that would timeout at startup when working on large sites on slow hosting
[FIX]: Fixed DupArchive timeout bug when working with large databases
INSTALLER
[NEW]: Bulk subsite import in multisite
[UPD]: Added validation test for REST API
[UPD]: Improved the database cleanup transients function which could timeout in large sites
[UPD]: Improved performance of the boot startup with the DupArchive
[UPD]: Now you can import non-complete packages into a multisite
[FIX]: Removed all the visible references to Duplicator in a branded installer
[FIX]: Removed some checks of the REST calls that caused the installation to fail in case of self signed certificate
[FIX]: iThemes Security and Easy HTTPS Redirection plugins automatically deactivated during installation
[FIX]: Fixed recovery package age in validation
[FIX]: chunked the table prefix replace regex to work with large number of tables
[FIX]: SAPI check now catches SAPI: apache2handler

**4.0.5.3 Patch **

Release Date: 2021-11-24
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.8.2

PLUGIN
Plugin [FIX]: Removed auto switch of client side kickoff when package determined stuck
Plugin [FIX]: Increasing time required that determines when a package is stuck - increases build reliability especially on slower systems

**4.0.5.2 Patch **

Release Date: 2021-11-22
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.8.2

PLUGIN
[UPD]: Updated certificate for SSL requests
INSTALLER
[UPD]: Updated certificate for SSL requests (Out of date certificates affected imports on some machines)

**4.0.5.1 Patch **

Release Date: 2021-11-8
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.8.2

PLUGIN
[FIX]: Fixed a warning message that appeared in case other plugins generated an unexpected output
INSTALLER
[NEW]: Implemented ZipArchive throttling
[NEW]: Added HTTP headers disabling caching during install
[FIX]: Charset and collate replace bug fixed
[FIX]: Fixed a bug when trying to duplicate a site in the same multisite
[FIX]: Automatically setting ZipArchive throttling for Siteground
[FIX]: Chunked the table prefix replace regex to work with large number of tables
[UPD]: Require site that is importing a package to run a version of Pro at or greater than the version that created the package
[UPD]: Improved instructions for manually removing the maintenance file generated by the installer.

4.0.5

Release Date: 2021-10-18
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.8

Overview:
The 4.0.5 release adds drag and drop installs of Duplicator Lite packages, advanced user import for multisite subsite installs and the official release of standalone to multisite subsite installs. Additionally, v4.0.5 includes many small improvements including UI tweaks and logic cleanup.

View All 4.0.5 Changes

PLUGIN
[NEW]: Plugin now capable of importing Duplicator Lite packages
[UPD]: Reduced queries executed in the frontend for better optimization
[UPD]: Improve the schedule ‘Run Now’ icon on the main packages page
[UPD]: Fix manual transfer status with OneDrive and improve UI workflow
[FIX]: Fixed the dead lock that occurred in some rare cases
[FIX]: Fixed autoselection of cPanel tab, when the ‘Auto Select cPanel’ checkbox for the Template is checked
[FIX]: Fixed an issue with the installer starting to import if loading a package after a migration
[FIX]: added check to make sure we are deleting the installer file at cleanup
[FIX]: Fixed autoselection of cPanel tab
INSTALLER
[NEW]: Standalone → Multisite subsite feature officially released
[NEW]: Advanced user import for multisite subsite installs (standalone and subsite sources)
[NEW]: Added next step and final report notices for config files in main folders
[NEW]: Added validation test and automatic search and replace for invalid MySQL engines
[NEW]: User mode added
[UPD]: Keep user now work on multisite
[UPD]: Improve wording for SHOW VARIABLE Validation check
[FIX]: Fixed multisite subsite import issue where Duplicator was activated both at the network level and subsite level

**4.0.4.1 Patch **

Release Date: 2021-9-8
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.8.1

PLUGIN
[NEW]: Added new streaming/fopen mode for Google Drive. Helps machines getting timeouts using cURL.
[FIX]: Addressed PHP 8 incompatibility with S3 functionality
INSTALLER
Installer [NEW]: Require user enter archive name on overwrites when default installer name used with no password (Enhances Security)
Installer [NEW]: Change default and show notice in case FORCE_ADMIN_SSL config is set and package is being installed with no SSL
Installer [FIX]: Fixed a problem on serialized strings that contained objects with properties with serialized strings

4.0.4

Release Date: 2021-8-16
PHP Version: 5.3.8 or higher

WordPress Version: 4.0 or greater
Tested up to: 5.8

Overview:
The 4.0.4 release was a culmination of many small improvements through-out the application including many UI improvements and cleanup. A major new feature is multisite subsite overwrite support which is part of our overall multisite support initiative.

View All 4.0.4 Changes

PLUGIN
[NEW]: Caches of many plugins are purged after a migration.
[NEW]: New scanner check for PHP 64-bit architecture for 2GB notices
[NEW]: Added outbound IP address to tools section
[NEW]: Added ability to run any package listed as recovery point directly in the package list
[NEW]: Added the possibility to download the recovery launcher
[NEW]: Now Duplicator PRO cannot be activated if LITE is active
[UPD]: Improved ZIP archive single and multi-threaded mode package creation speed
[UPD]: Improved message shown when storage endpoint can’t be read
[UPD]: Changed coloring of delete package import message
[UPD]: Additional polish and cleanup of license messages
[UPD]: Improve Package Details Error notice message
[UPD]: Removed old webfont files and references
[UPD]: Improve help and enhance the visibility of the Import UI Screens
[UPD]: Fixed ‘use current’ quick link in installer section of first page of build
[UPD]: Updated recovery feature UI on package list page
[UPD]: Updated filter selection UI on tables to work on large number of tables (10K tables tested).
[UPD]: Updated the parsely library to version 2.9.2
[UPD]: Updated the duplicator_pro_entities table to handle larger serialized objects
[UPD]: Updated for WordPress 5.8
[FIX]: No longer removing corrupt tables from list of tables available for filtering on build step 1
[FIX]: Fixed tables filter with hight number of tables selected
[FIX]: Updated the list of filtered tables in the package details (previously they were not displayed)
[FIX]: Added logic to show quick fix when ZipArchive failed in various places
[FIX]: Copying a template to another template, in some cases the source template ID was not handled correctly
[FIX]: Send email when schedule errors out due to requirements failing
INSTALLER
[NEW]: Hooks system added installer
[NEW]: added option that allows one to remove definer statements from create queries
[NEW]: Subsite to multisite overwrite function enabled
[NEW]: Addon system implemented installer
[NEW]: Remove only media option added
[NEW]: Validation test added that shows a list tables that are affected by the database action.
[UPD]: Updated UI elements when no triggers present
[UPD]: Improved restore backup mode installer selection
[UPD]: Removed old webfont files and references
[UPD]: Now the new URL is editable only in advanced mode
[UPD]: Improved bulk DELETE and UPDATE queries by chunking them
[FIX]: Ignore cPanel pre-fills from package creation step 1 in case of an import install
[FIX]: Fixed the selection of tables to be extracted in advanced mode with large number of tables
[FIX]: Fixed bug with tables that are removed in import validation when import option of subsite enabled

**1.5.0 **Latest-Stable****

Release Date: 2022-08-28
PHP Version: 5.3.8 or higher

PLUGIN
[FIX]: Fixed timezone and server time strings in the “Tools” screen
[FIX]: Fixed bug related to storage path changing when trace log is enabled
[FIX]: Fix package active after restoring a backup
[UPT]: Improved the icons and wording around the installer save as file name check
[UPT]: Improved the packages detail screen better represent the logic that downloads files
INSTALLER
[NEW]: Basic mode is now enabled with a two-step process (vs 4 step advanced process)
[NEW]: Step 1 - New Database Action - Backup Existing Tables
[NEW]: Step 1 - New Database Action - Skip Database Extraction
[NEW]: Step 1 - Advanced - New Server Throttling and Chunking for Zip Formats
[NEW]: Step 1 - Advanced - New Database Processing Chunking mode
[UPT]: Step 1 - Advanced - Improve the Configuration files setup options
[UPT]: Step 1 - Validation checks improved to support more scenarios
[UPT]: Step 1 - Install Confirmation improved notice for existing database tables
[NEW]: Step 2 - Include/Exclude database tables and new UI interface
[NEW]: Step 3 - New features for WordPress Admin Accounts
[NEW]: Step 3 - New interface for plugin setup and wp-config files
[UPT]: Step 4 (2 Basic) - Improved validation checks when processing is completed
[UPT]: The help system has been improved to better cover all features

**1.4.7.2 **Latest-Stable****

Release Date: 2022-08-15
PHP Version: 5.3.8 or higher

PLUGIN
[UPD]: Update plugin fatal error edge case on some machines. [source 1]
[UPD:] Improve plugin removal cleanup
[UPD:] Improve installer file storage access

1.4.7.1

Release Date: 2022-08-03
PHP Version: 5.3.8 or higher

PLUGIN
[UPD]: Minor security tweaks for some edge cases.

1.4.7

Release Date: 2022-06-27
PHP Version: 5.3.8 or higher

PLUGIN
[UPD]: On the build step 1 setup section, fix expand/collapse icon to better alignment.
[UPD]: Improve the installer options quick link description area when a build is completed.
INSTALLER
[UPD]: Remove server path info on the server details information popup window.
[UPD]: Improve cleanup process and fix installer link showing in output with query string.

1.4.6

Release Date: 2022-5-19
PHP Version: 5.3.8 or higher

PLUGIN
[UPD]: Improve wording on build step 3 for how to start the install process
[UPD]: Scanner ‘Migration Status’ moved from Archive area to Setup area
[UPD]: Improve archive filter tips to have better separation and spacing
[FIX]: Build step 2 scanner sub “upload” folders are not checkable
INSTALLER
[UPD]: Improve messaging for managed hosting platforms that only support the Pro product

1.4.5

Release Date: 2022-04-13
PHP Version: 5.3.8 or higher

PLUGIN
[UPD]: Improve plugin icons to better reflect the most recent updates
[UPD]: Improve plugin layouts on package build forms and on package details
[UPD]: Improve package details screen in-sync with Pro version
[UPD]: Removed database.sql visibility in backup directory and from download on details screen
[UPD]: Improve the build interrupt screen to better handle additional scenarios beyond server timeouts
[UPD]: Improve support for PHP 8.1 by removing various warnings and notices from the error log
INSTALLER
[UPD]: Improve the table database collation support to better detect cross compatibility collations issues. [source 1] [source 2]
[UPD]: Improve support for PHP 8.1 by removing various warnings and notices from the error log

1.4.4

Release Date: 2022-02-01
PHP Version: 5.3.8 or higher

PLUGIN
[UPD]: Duplicator logo and favicon from blue to red
[FIX]: Single quote in user’s folder path was causing javascript error in console [source]
[NEW]: On Build Status screen new option to show installer name and improved layout of screen
INSTALLER
[UPD]: Improve archive not found message in the installer boot-loader screen
[UPD]: Updated the wordings and added helper text for ‘Config Files’ option under ‘Advanced’ settings on step 1 [source]
[UPD]: Fixing legacy references for log() static call $this instead of “self::”
[UPD]: Improve messaging and workflow of safe mode settings and content
[UPD]: Improve visual layout to more closely stay in sync with the Pro version.
[UPD]: Improve support for PHP version 8.1.1.

1.4.3

Release Date: 2021-09-08
PHP Version: 5.3.8 or higher

PLUGIN
[FIX]: Scanner bug if $check var is not a valid boolean type
[FIX]: Warning: for function ‘duplicator_global_scripts’ not found
[UPD]: Changed Tools ❯ Diagnostics to “General” to match Pro version
[UPD]: Improve installer help links on build status
[UPD]: Notices for no-support on Duplicator Lite multisite
[UPD]: Removed old font-awesome web-font files and references for legacy browsers
[UPD]: Changed UTM content of various links and fixed some broken ones
INSTALLER
[UPD]: Removed old font-awesome web-font files and references for legacy browsers
[UPD]: Step 1 & 2 Validation section at bottom to match Pro setup
[UPD]: Archive file name input on installer screen for non localhost installs

1.4.2

Release Date: 2021-07-07
PHP Version: 5.3.8 or higher

PLUGIN
[UPD]: Improve filesize checks that return filesize stat warnings
[UPD]: Warning on packages page if trace logging is enabled, with notice to turn off
[UPD]: Add support for some PHP-8 hosts that do not support shell_exec
[UPD]: Harden the installer rename process when the normal installer file is present
[FIX]: Issues in some PHP versions with paths replaced relative path includes with absolute paths
[FIX]: Layout of file cleanup notice properly shows under page header title
INSTALLER
[UPD]: Wording and layout improvements in various steps
[UPD]: Harden installer.php rename logic for general installer name.

1.4.1

Release Date: 2021-05-26
PHP Version: 5.3.8 or higher

PLUGIN
[UPD]: Both Lite and Pro plugins cannot be active at same time messages
[UPD]: Improve wording for PHP 5.2 notice and Settings CSS JSS Hooks
[UPD]: Added a check to build scan process when SQL FUNCTIONS are present
[BUG]: Download archive on some hosts having issues. Using content_url() WP_CONTENT_URL to get url
[BUG]: Added default value to DUP_Log::error detail argument to fix php log errors [source].
INSTALLER
[NEW]: Added better handling of SQL FUNCTIONS
[UPD]: Improved CSRF error handling
[UPD]: Updated to Handlebars 4.7.7 on both plugin and installer

1.4.0

Release Date: 2021-03-02
PHP Version: 5.3.8 or higher

PLUGIN
[BUG] On some setups eval in JS causes issues (eval removed).
[UPD] Additional improvements for PHP 8 support
[UPD] Packages view ‘Installer name’ setting link moved to lock icon
[NEW] Notice: PHP version check minimum PHP 5.3.8
[NEW] Notice: future warning that LITE and PRO cannot be activated at same time
[NEW] Notice: For MU usage plugin must be installed at network not sub-site.
[NEW] Notice: Show admin alert when export capability isn’t present
[NEW] Add MySQL TRIGGER management on PHP dump and installer checks
INSTALLER
[BUG] On some setups eval in JS causes issues (eval removed). [BUG] Collation fallback not working correctly.
[BUG] Replace host in DEFINER statement to %in case of remote hosts
[NEW] Managed host detection conflict detection
[NEW] Site Overwrite support for existing WP sites
[NEW] Add option to remove DEFINER from PROCEDUREs

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907