Bug fix: Security: Plugin configuration data now uses JSON encoding instead of serialization to prevent PHP Object Injection (thanks to Patchstack for responsible disclosure on January 15, 2024 followed by development and testing of the fix by WP Engine)
Bug fix: Security: Unserializing an object during find and replace operations now passes 'allowed_classes' => false to avoid instantiating the complete object and potentially running malicious code stored in the database
Bug fix: Security: The wp-queue library now ensures that only its own classes can be unserialized via allowed_classes
Bug fix: Sites with "bundle" or "runtime" in the domain name can now load plugin pages in WP Admin