| @@ -3,9 +3,9 @@ | ||
| 3 | 3 | Tags: forms, form builder, custom form, contact form, payment form |
| 4 | 4 | Requires at least: 6.3 |
| 5 | 5 | Tested up to: 7.1 |
| 6 | 6 | Requires PHP: 7.0 |
| 7 | -Stable tag: 6.34 | |
| 7 | +Stable tag: 6.35 | |
| 8 | 8 | |
| 9 | 9 | The most powerful drag and drop WordPress form builder for contact forms, payment forms, calculators, quizzes, surveys, and data-driven applications. |
| 10 | 10 | |
| 11 | 11 | == Description == |
| @@ -364,8 +364,36 @@ | ||
| 364 | 364 | |
| 365 | 365 | See all [Formidable Zapier Integrations](https://zapier.com/apps/formidable/integrations). |
| 366 | 366 | |
| 367 | 367 | == Changelog == |
| 368 | += 6.35 = | |
| 369 | +* Security: More strict sanitizing is now applied to entry key values before it gets used in the HTML of a form. | |
| 370 | +* Security: The value that records who last saved an entry is now always set from the current user, not allowing for any custom values unless importing. | |
| 371 | +* New: The shortcodes list now offers show options for more types, and long names are truncated so the list stays readable. | |
| 372 | +* New: The Processor column on the Payments list page can now be sorted. | |
| 373 | +* New: A message is now shown on the Payments list page after bulk deleting. | |
| 374 | +* New: The required email input used for Stripe Link payments will now display a required asterisk like other required inputs. | |
| 375 | +* New: A new frm_builder_after_field_label hook has been added for adding content after a label in the builder. | |
| 376 | +* New: A new frm_payment_user_id filter has been added for setting which user a payment belongs to. | |
| 377 | +* Performance: The builder now loads much faster when there are a lot of fields. Fields loaded with AJAX are now loaded in asynchronous batches. | |
| 378 | +* Performance: The way the denylist is checked has been optimized, so spam checks are much faster when a large amount of text is submitted. | |
| 379 | +* Performance: Pricing updates for Stripe payments are now debounced, and are skipped on pages with no payment intents. | |
| 380 | +* Fix: A subscription would not get cancelled after it reached its Recurring Payment Limit. | |
| 381 | +* Fix: Payment status actions could run twice for the same Stripe Link payment. | |
| 382 | +* Fix: Multiple customer objects would get created for Stripe Link recurring payments. | |
| 383 | +* Fix: Subscription plan details would not update after changing the trial period. | |
| 384 | +* Fix: A Stripe Link redirect would use the URL from Form settings instead of the URL in the confirmation action that ran. | |
| 385 | +* Fix: Square payments would not correctly follow conditional logic when two Square actions were used. | |
| 386 | +* Fix: The wrong amount would get used when verifying a buyer with Square. | |
| 387 | +* Fix: Connecting and disconnecting Square would go by whichever mode was active instead of the mode that was selected. | |
| 388 | +* Fix: In Pro, the dropdown on a style card would not populate, leaving no way to delete a style or set one as the default. | |
| 389 | +* Fix: In Pro, a section added after a partially sized field would move into the previous row after a reload. | |
| 390 | +* Fix: Adding the frm_first layout class would not start a new row for a group. | |
| 391 | +* Fix: A field id used in a description would not get switched when a form was duplicated or imported. | |
| 392 | +* Fix: Creating a field with a missing or invalid options value would raise a PHP warning and store null. | |
| 393 | +* Fix: The Embeds column would only update when a post was inserted, so it went stale when a page was updated or deleted. | |
| 394 | +* The old hard coded widths for the frm_grid_2 through frm_grid_10 classes have been removed from the generated stylesheets, helping to reduce the file size of styles used on the front end. | |
| 395 | + | |
| 368 | 396 | = 6.34 = |
| 369 | 397 | * Security: Additional validation has been added to guarantee that submitted HTML in form data by untrusted users cannot be used for XSS. |
| 370 | 398 | * New: Address fields are now included in Lite! |
| 371 | 399 | * New: Address field data is included in PayPal Commerce credit card payments when defined in payment action settings to help prevent entries from incorrectly getting flagged as fraudulent. |
| @@ -377,26 +405,9 @@ | ||
| 377 | 405 | |
| 378 | 406 | = 6.33.1 = |
| 379 | 407 | * Fix: Public taxonomy pages could result in 404 errors, caused by a missing check in the new Gated Content actions. |
| 380 | 408 | |
| 381 | -= 6.33 = | |
| 382 | -* New: A new Gated Content form action type has been added. Now you can easily give access to restricted pages, views, pdfs, and files! | |
| 383 | -* New: A new Spam settings section has been added to Form settings. Several spam settings have been moved here. In addition this section includes a summary of Global Spam settings, and a new Include Captcha in this form setting to easily add and remove Captcha fields. | |
| 384 | -* New: PayPal Commerce front end error messages have been improved. | |
| 385 | -* New: A Payment Settings button has been added to the Payments list page. | |
| 386 | -* Fix: Google Pay would use the test environment incorrectly when using PayPal Commerce. | |
| 387 | -* Fix: A Using null as an array offset is deprecated, use an empty string instead PHP deprecated message has been fixed. | |
| 388 | - | |
| 389 | -= 6.32.1 = | |
| 390 | -* Security: An issue has been fixed where requests could be manipulated to attempt form submissions using test payments instead of live payments, for Stripe, Square, and PayPal Commerce. | |
| 391 | -* Security: An incorrect status check would allow forms to submit without errors when using PayPal Commerce to handle subscriptions in a pending approval status. Credit to Yaswanth Reddy Sunkara and WPScan for reporting the issue. | |
| 392 | -* Security: Additional validation has been added to guarantee a PayPal Commerce Apple Pay payment has the correct status. | |
| 393 | -* Fix: A cron job for handling overdue subscriptions would not properly get unscheduled after disconnecting Square and PayPal. | |
| 394 | -* Fix: The PayPal Commerce test mode option would not properly update on save when the PayPal add-on was also active. | |
| 395 | -* Fix: Email settings in payment actions would incorrectly display autofill options in Safari. | |
| 396 | -* Options to use credit cards in PayPal Commerce subscriptions has been removed as it did not properly work. | |
| 397 | - | |
| 398 | 409 | [See changelog for all versions](https://raw.githubusercontent.com/Strategy11/formidable-forms/master/changelog.txt) |
| 399 | 410 | |
| 400 | 411 | == Upgrade Notice == |
| 401 | -= 6.34 = | |
| 402 | -This version fixes a security-related bug. Upgrade immediately. | |
| 412 | += 6.35 = | |
| 413 | +This version fixes security-related bugs. Upgrade immediately. | |