Recent Updates
Security
- Improved validation of PayPal Standard IPN notifications.
Fixes
- Resolved an issue where PayPal Standard donations and subscription renewals with recovered fees were not recorded after the IPN validation update.
Security
- Hardened the handling of group purchase options when adding products to the cart.
Security
- Improved output escaping for block attributes.
- Improved output handling in multiple blocks.
Security
- Improved output escaping for block attributes.
- Improved output handling in multiple blocks.
Fixes
- Corrected the ticket sale duration date picker so it closes when clicking elsewhere in the editor, and gave new tickets a one day sale window when the event has no dates saved yet, instead of an invalid end date.
- Kept an event’s payment provider when its ticket settings are saved, and left the provider selectable until the first ticket (not an RSVP) is created.
Security
- Hardened the permission and state handling of QR code check-in notices.
- Strengthened validation of RSVP orders placed through the REST API.
- Tightened the permission checks for regenerating the QR code API key.
Tweaks
- Centered the labels of the secondary buttons in the ticket admin panels, including the settings button icon, so they line up vertically within the button.
Languages
- 3 new strings added, 64 updated, 0 fuzzied, and 0 obsoleted.
Fixes
- Updated the RSVP attendee fields modal CSS ID in the classic editor after the RSVP v2 metabox moved to its own form container.
Fixes
- Prevented the Tickets metabox from losing fields in the Classic Editor when the RSVP metabox is placed above it.
Enhancements
- Improved donations list table performance on sites with hundreds of thousands of donations by paging on IDs first, fixing the total count query, and replacing the single-column donation meta indexes with composite ones
- Improved the Reports screen and legacy earnings stats on large sites by summing and counting donations in the database instead of loading every donation into memory
- Improved donation processing speed by skipping unnecessary offline donation email checks
Fixes
- Recurring donation stats on the campaigns list now read from the cache correctly instead of showing empty values
- Campaign stats now show for campaigns that were added after the stats cache was built
- Resolved an issue where campaign stats showed as zero after viewing the Campaigns screen with test mode enabled
- Donations list table was running extremely slowly and including trashed donations on large sites.
- Resolved an issue where a database error while saving a donation, donor, subscription, campaign, or event caused a critical error and hid the real cause
- Resolved an issue where sites running PHP 8.4 or newer logged deprecation notices from GiveWP
- Database migrations started a second time in requests that arrive while a slow migration is still running. Now it runs one time and the migrations list now shows the latest run first.
- Resolved an issue where a PHP warning could appear on development copies of GiveWP that have not been built
- Resolved an issue where subscription webhook events caused a fatal error when the subscription had no initial donation
- Updated campaign duplication to create a single copy of each associated form when form metadata contains duplicate keys.
- Restored donor names, initials, and totals on the donor wall block and shortcode.
Security
- Enhanced security in Stripe webhook module
- Enhanced security on the campaign block. (CVE-2026-97643)
- Enhanced security for the Donor Dashboard access.
Fixes
- Resolved an issue where duplicating a donation form created a duplicate Recurring Donations goal format setting
Fixes
- Resolved 404 errors when loading settings for features.