Recent Updates
Security
- Tightened security around database upgrades.
Fixes
- Further reduced database load from the Hide Restricted Posts filtering on REST API and query requests.
- Activation and test emails no longer fail to send when an email template field was left blank.
- Corrected the plugin’s translation file path so bundled language files load correctly.
- Prevented gateway labels from being translated before the plugin’s translations were ready, which could trigger a PHP notice.
Security
- Strengthened input sanitization and output escaping in Kadence Blocks forms.
Fixes
- Resolved a fatal error when GoCardless account-level webhooks referenced subscriptions that do not exist in GiveWP
Fixes
- Resolved a fatal error when the REST API index was requested in help context.
Security
- Strengthened output escaping in the form entries views.
Fixes
- Resolved a PHP 8 fatal error on the donation details screen when the global Tribute Options have never been saved.
Fixes
- Resolved an issue where donations with the Mailchimp opt-in selected could fail when the audience list contained duplicate or empty entries.
Security
- Strengthened validation of copied widget instances.
Security
- Improved validation of the event tickets purchase flow.
- Added additional validation to PayPal Commerce completed-order processing.
- Added additional validation to donor email lookups. Thanks Jakub Herman for responsibly disclosing this issue.