Events
Recent Updates
Fixes
- Hardened the restoration of saved filter sets against a security vulnerability.
Fixes
- Removed the previously saved values of a checkbox Additional Field when every option is unselected and the event is updated.
- Resolved two PHP 8 fatal errors in recurring events: describing a yearly rule with no months selected, and generating a series when an instance could not be inserted.
Languages
- 0 new strings added, 36 updated, 0 fuzzied, and 0 obsoleted.
Compatibilitys
- Registered the plugin's editor blocks with Block API version 3 so they render correctly inside the iframed block editor introduced in WordPress 6.9.
Fixes
- Prevented event pages and iCal exports from failing when event descriptions contain Single Event or Events Archive blocks.
- Resolved an issue where hiding the subscribe links with a snippet that returns a non-array value from the
tec_views_v2_subscribe_linksfilter could cause a fatal error on single event pages. - Resolved fatal errors that could occur when WordPress or another plugin passed unexpected data to The Events Calendar, such as while SiteGround Optimizer clears its cache.
Languages
- 0 new strings added, 59 updated, 0 fuzzied, and 0 obsoleted.
Security
- Hardened access checks on REST API responses. Props to Kaveesha Nirmal for reporting.
- Strengthened permission checks in the REST API v1. Props to Mohammed Abd Alrahman for reporting.
Fixes
- Dropped the cached calendar-view ticket data when tickets are sold and when the plugin updates, instead of rebuilding it mid-order, resolving an issue where sold-out events kept showing the remaining ticket count on calendar and list views.
- Fixed an issue where a custom ticket sale end date set during ticket creation in the block editor reverted to the event start date after saving the event.
- Renewed the Square access token ahead of its expiration and retried a rejected request once against the fresh one, which kept Tickets Commerce checkout from failing about 30 days after connecting to Square. Where Square would neither renew the credentials nor accept the stored token, the gateway reported itself as disconnected with an admin notice instead of showing a healthy connection while live charges failed.
- Resolved a fatal error that could occur while rendering the Move Attendees dialog when another plugin listened on the admin_enqueue_scripts action.
- Resolved an issue where the tickets and attendees REST API archives could return a JSON object instead of an array when an entry could not be formatted, preventing the Event Tickets Plus App from listing attendees.
- Stripe checkout could return a server error and never charge the buyer when a coupon changed the cart total, because the application fee left on the Payment Intent no longer matched the discounted amount.
Languages
- 7 new strings added, 153 updated, 0 fuzzied, and 1 obsoleted.
Security
- Tightened the handling of Assigned Seating reservations, covering the seat labels stored against attendees and the session tokens reservations are filed under.
Security
- Strengthened validation of copied widget instances.
Fixes
- Resolved an issue where selected options in a Checkbox Additional Field appeared unchecked while its block was focused in the block editor.
Languages
- 0 new strings added, 0 updated, 0 fuzzied, and 0 obsoleted.
Fixes
- Resolved an issue where the Day View direct URL omitted recurring event occurrences because an earlier query on the same repository froze the custom tables date redirection.
- Fixed a fatal error when reading an event's venues or organizers on sites running a persistent object cache, caused by a cached lazy collection losing the callback it needs to rebuild itself. Also added the
tec_events_lazy_post_collection_allowed_unserialize_callbacksfilter so third-party code can register its own rebuild callbacks.
Languages
- 0 new strings added, 100 updated, 0 fuzzied, and 0 obsoleted.
Fixes
- Prevented a fatal error when viewing a WooCommerce order or attendee information for a ticket whose product has been permanently deleted.
Languages
- 0 new strings added, 11 updated, 0 fuzzied, and 0 obsoleted.
Fixes
- Resolved a fatal error that could be triggered in the Tickets Commerce cart when the decoded ticket data was null.
- Prevented the cart-to-checkout redirect and the checkout page from being stored by full-page and edge caches, resolving an issue where the Tickets Commerce checkout could show 'Oops, no tickets!' after selecting tickets.
Languages
- 5 new strings added, 75 updated, 0 fuzzied, and 9 obsoleted.
Security
- Harden capability checks on REST API archive endpoints
- Harden validation of copied widget instance data