Recent Updates
Fixes
- Improved data sanitization and output escaping.
Updates
- Improved translations, theme headers and image sizes.
Fixes
- Improved data sanitization and output escaping.
Updates
- Improved translations, theme headers and image sizes.
Fixes
- Improved data sanitization and output escaping.
Updates
- Improved translations, theme headers and image sizes.
Security
- Hardened security around team updates (CVE-2026-82663) and campaign sorting (CVE-2026-82568)
Fixes
- Enhanced security around the eCard recipient data. (CVE-2026-19658)
Fixes
- Resolved an issue where selected options in a Checkbox Additional Field appeared unchecked while its block was focused in the block editor.
Languages
- 0 new strings added, 0 updated, 0 fuzzied, and 0 obsoleted.
Fixes
- Resolved an issue where the Day View direct URL omitted recurring event occurrences because an earlier query on the same repository froze the custom tables date redirection.
- Fixed a fatal error when reading an event's venues or organizers on sites running a persistent object cache, caused by a cached lazy collection losing the callback it needs to rebuild itself. Also added the
tec_events_lazy_post_collection_allowed_unserialize_callbacksfilter so third-party code can register its own rebuild callbacks.
Languages
- 0 new strings added, 100 updated, 0 fuzzied, and 0 obsoleted.
Fixes
- Prevented a fatal error when viewing a WooCommerce order or attendee information for a ticket whose product has been permanently deleted.
Languages
- 0 new strings added, 11 updated, 0 fuzzied, and 0 obsoleted.
Fixes
- Resolved a fatal error that could be triggered in the Tickets Commerce cart when the decoded ticket data was null.
- Prevented the cart-to-checkout redirect and the checkout page from being stored by full-page and edge caches, resolving an issue where the Tickets Commerce checkout could show 'Oops, no tickets!' after selecting tickets.
Languages
- 5 new strings added, 75 updated, 0 fuzzied, and 9 obsoleted.
Fixes
- Fixed a campaign's default donation form appearing unpublished in the form builder.
- Fixed PHP warnings on the form builder screen when its page is opened without the locale or donation form ID query arguments.
- Resolved a plugin conflict that prevented donor first and last names from being recorded when the Charitable plugin was active alongside GiveWP.
- Resolved an issue where the custom amount minimum and maximum also applied to the donation levels and the set donation amount, so a level below the minimum could not be donated. Forms that leave the minimum empty now fall back to the lowest configured amount, and a minimum or maximum with cents is no longer rounded down.
Security
- Removed vulnerable dead code related to legacy donor relinking. (CVE-2026-82676)
- Enhanced security on donor account access. (CVE-2026-82675)
Tweaks
- Replaced the axios HTTP client with WordPress core's apiFetch in the donor dashboard, reports, onboarding wizard, and the log and migration list tables, and removed axios from the plugin's JavaScript dependencies.