Free v3.8.8 with security fixes and hardenings is available

Posted on 13 April, 2014

Category:

Free-Version Releases
Attention: this is not the changelog for the latest stable version 4.28 (see related release notes)

In the last few days, the openssl heartbleed bug lead to a global awareness that IT security is essential nowadays. Maps Marker Pro (respectively our servers) were not affected by this bug, nevertheless delivering a secure plugin has always been a high priority in development.

With v3.8.7, the results from the second security audit by the City of Vienna were implemented and with this release, I did another security audit on my own to further improve the security of Maps Marker Pro.

As a result of this audit, some potential cross site scripting issues were also fixed. Please note that an attacker would have needed access to a WordPress admin user in order to exploit those and it would have been rather unlikely that an attacker would target Maps Marker Pro for e.g. defacing a site, when having access to a WordPress admin user would allow him to change template files or even get access to the database credentials in wp-config.php. Nevertheless, these low-critical issues are now fixed with v3.8.8.

For even more features and optimizations (see the comparision page), please use the integrated pro upgrader to start a free 30-day-trial of Maps Marker Pro.

Pro v1.5.9 has also been released today with the following highlights:


Let me know what you think about this new release by submitting a review!

If you want to keep up to date with the latest Maps Marker development, please follow @MapsMarker on twitter (= most current updates), on FacebookGoogle+ or subscribe to news via RSS or via RSS/email.

I would also like to invite you to join our affiliate program which offers commissions up to 50%. If you are interested in becoming a reseller, please visit https://www.mapsmarker.com/reseller


Now lets get to the highlights of free v3.8.8:

Other optimizations and changes

  • show warning message if incompatible plugin “Root Relative URLs” is active (thx Brad!)
  • remove plugin version used from source code on frontend to prevent information disclosure

Bugfixes

  • fixed potential XSS issues (exploitable by admins only)
  • attribution for mapbox 2 basemap was wrong on marker and layer edit pages
  • WMS demo layer “Vienna public toilets” was not shown on KML view (fixed on new installations only to not overwrite existing custom settings)
  • Certain types of apostrophes in addresses could break marker maps on backends

Translations updates

Thanks to many motivated contributors, this release comes with the following updated translations:

  • Chinese translation thanks to John Shen, http://www.synyan.net and ck
  • Dutch translation thanks to Patrick Ruers, http://www.stationskwartiersittard.nl
  • German translation
  • Russian translation thanks to Ekaterina Golubina (supported by Teplitsa of Social Technologies – http://te-st.ru) and Vyacheslav Strenadko, http://poi-gorod.ru
  • Turkish translation thanks to Emre Erkan, http://www.karalamalar.net and Mahir Tosun, http://www.bozukpusula.com

If you want to contribute to translations (new Hindi translators would be appreciated!), please visit https://translate.mapsmarker.com/projects/lmm for more information. Please note that translators are also compensated for their contribution – for example if a translation is finished less than 50%, the translator gets a free 25 licenses pack worth €149 as a compensation for completing the translation to 100%.

Outlook – my plans for the next release

Please see the roadmap for a rough schedule for planned features of the pro version and please subscribe to this blog (via RSS or Email) or follow @MapsMarker on twitter (= most current updates) if you want to stay up to date with the latest development news.

Full changelog

Maps Marker Pro reseller program launched – see https://www.mapsmarker.com/reseller for more details
Maps Marker Pro licenses now available also with 3 and 5 years access to updates and support
show warning message if incompatible plugin “Root Relative URLs” is active (thx Brad!)
remove plugin version used from source code on frontend to prevent information disclosure
fixed potential XSS issues (exploitable by admins only)
attribution for mapbox 2 basemap was wrong on marker and layer edit pages
WMS demo layer “Vienna public toilets” was not shown on KML view (fixed on new installations only to not overwrite existing custom settings)
Certain types of apostrophes in addresses could break marker maps on backends
Translation updates
In case you want to help with translations, please visit the web-based translation plattform
updated Chinese translation thanks to John Shen, http://www.synyan.net and ck
updated Dutch translation thanks to Patrick Ruers, http://www.stationskwartiersittard.nl
updated German translation
updated Russian translation thanks to Ekaterina Golubina (supported by Teplitsa of Social Technologies – http://te-st.ru) and Vyacheslav Strenadko, http://poi-gorod.ru
updated Turkish translation thanks to Emre Erkan, http://www.karalamalar.net and Mahir Tosun, http://www.bozukpusula.com

show previous changelogs

How to download / update 

The easiest way to update is to use the WordPress update process: login with an user who has admin privileges, navigate to Dashboard / Updates, select plugins to update and press the button “Update Plugins”. Alternatively you can also download the current version here, unzip the package and overwrite the plugin´s files on your webserver.