Hey everyone 👋
This one is small but worth taking. We closed a security hole in Page Headers where the layout setting could be pointed at files it had no business loading. Alongside it: two blank screens are gone, version rollback behaves itself again, and the Blog spacing controls finally explain what they affect.
Let’s get into it.
🔧 Better than before
- Blog spacing controls now tell you what they actually affect. The “Inside” and “Outside” spacing options under Blog Post spell out which container layouts and styles they apply to, so you’re not left guessing why a value did nothing.
🐛 Squashed
- Page Headers can no longer be pointed at arbitrary files on your server. The layout setting accepted any value, so a crafted one could pull in PHP files that were never meant to be templates. It’s now restricted to Astra Pro’s own templates. This is a security fix.
- Rolling back twice in a row now works. Choosing an older version a second time quietly reinstalled the latest one instead of the version you picked. Squashed.
- The Customizer no longer goes blank on locked-down servers. On hosts without direct file write access, opening or saving the Customizer could run out of memory and leave you staring at a white page. Fixed.
- Site Builder Display Conditions opens on layouts with no rules set. An empty display rule set sent you to a blank screen, and it broke the layout settings panel in the editor too. Both gone.
We recommend updating as soon as you can.
As always, support is one click away if anything feels off.
— Team Astra