github msrbuilds/elementor-mcp v3.19.2
EMCP Tools 3.19.2

4 hours ago

EMCP Tools 3.19.2

Security update with review hardening for OAuth, menus and loops, and Cloud Safe Updates for reviewing plugin, theme and WordPress updates with a snapshot and automatic restore.

  • New: Cloud Safe Updates. From Account → Safe updates on EMCP Cloud, workspace owners can review the plugin, theme and WordPress updates a connected site has waiting and run them in groups. Each group gets a file and database snapshot first; the site shows a short maintenance page while it runs, chosen pages are checked afterwards, and a failed group is restored from its snapshot. Nothing starts without the owner's maintenance consent, the plugin never accepts download links, and sites it cannot recover safely (no HTTPS, multisite, must-use plugins, custom content paths, files it cannot write, another WordPress install sharing the database table prefix) are refused before anything changes, and the files at fault are named. If EMCP Cloud stops responding before any update has run, the site reopens by itself at the job deadline; once an update may have run, it stays in maintenance until Cloud restores it. A restore interrupted by a host time limit resumes where it stopped, and a finished job keeps only its status receipt: its snapshots and database credentials are deleted, and uninstalling removes finished job folders. The new cloud-safe-updates tool is under Tools → EMCP Modules → EMCP Cloud.

  • Security: Restrict credentialed Unsplash requests to the exact trusted HTTPS origin and disable redirects, preventing API key disclosure through crafted image URLs.

  • Security: Require management authorization and a valid settings nonce before interpreting posted tool toggles, preventing unauthorized changes during pending defaults updates.

  • Security: OAuth and request handling are stricter. Request values are type checked before they are used, malformed bearer tokens, hosts and client addresses are refused instead of being reinterpreted, the sign-in return address uses the configured site origin, and the consent page can no longer be framed by another site.

  • Security: Menu output is filtered, Elementor notices only show on EMCP screens, and the consent, menu icon, SVG and loop styles load through WordPress's own queues. Loop pages load their scripts with WordPress's own printers.

  • Security (Pro): EMCP Themer's condition search checks its inputs and only returns posts you can read, and the Widget Builder's current page links are normalized.

Downloads and updating

  • Free: download the attached emcp-tools-3.19.2.zip, or update from your WordPress dashboard. The admin source is in this repository at tag v3.19.2.
  • Pro: update through Freemius with an active license.
  • Cloud Safe Updates needs 3.19.2 on the site; once updated, a connected site appears under Account → Safe updates on EMCP Cloud.

Requires WordPress 6.9+ and PHP 8.1+.

Don't miss a new elementor-mcp release

NewReleases is sending notifications on new releases.