Decryption key:
Greenshift Page Builder + Addons v13.2.0 Nulled
= 13.2.0 =
* Fixed: Stored XSS in GSAP animation data attributes - the customProps, customPropsM and multianimations values are now HTML escaped before they are written into the block markup, so a value saved by a lower privileged user (Contributor and up) can no longer break out of the attribute and inject an event handler. Reported by Revanth Hari Narayana Matte
* Fixed: Server Side Request Forgery in the CSV to JSON REST endpoint - CSV imports are now limited to Google Sheets hosts (docs.google.com, spreadsheets.google.com) over https instead of fetching any URL the request asks for. Reported by Alireza Kalhor
* Added: gspb_allowed_csv_hosts filter, for site owners who host their CSV data on another trusted host
* Fixed: chart CSV link is now URL encoded when it is passed to the CSV endpoint, so published Google Sheets links with several query parameters are no longer truncated