PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.18.0
GiveWP – Donation Plugin and Fundraising Platform v4.18.0
4.18.0 4.17.0 4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 All 257 releases
← All changes | changelog.txt +64 -0 4.16.6 → 4.18.0 View file →
@@ -1,6 +1,70 @@
1 1 == Changelog ==
2 2
3 += 4.18.0: October 1st, 2026 =
4 +* Enhancement: Improved donations list table performance on sites with hundreds of thousands of donations by paging on IDs first, fixing the total count query, and replacing the single-column donation meta indexes with composite ones
5 +* Enhancement: Improved the Reports screen and legacy earnings stats on large sites by summing and counting donations in the database instead of loading every donation into memory
6 +* Enhancement: Improved donation processing speed by skipping unnecessary offline donation email checks
7 +* Fix: Recurring donation stats on the campaigns list now read from the cache correctly instead of showing empty values
8 +* Fix: Campaign stats now show for campaigns that were added after the stats cache was built
9 +* Fix: Resolved an issue where campaign stats showed as zero after viewing the Campaigns screen with test mode enabled
10 +* Fix: Donations list table was running extremely slowly and including trashed donations on large sites.
11 +* Fix: Resolved an issue where a database error while saving a donation, donor, subscription, campaign, or event caused a critical error and hid the real cause
12 +* Fix: Resolved an issue where sites running PHP 8.4 or newer logged deprecation notices from GiveWP
13 +* Fix: Database migrations started a second time in requests that arrive while a slow migration is still running. Now it runs one time and the migrations list now shows the latest run first.
14 +* Fix: Resolved an issue where a PHP warning could appear on development copies of GiveWP that have not been built
15 +* Fix: Resolved an issue where subscription webhook events caused a fatal error when the subscription had no initial donation
16 +* Fix: Updated campaign duplication to create a single copy of each associated form when form metadata contains duplicate keys.
17 +* Fix: Restored donor names, initials, and totals on the donor wall block and shortcode.
18 +* Security: Enhanced security in Stripe webhook module
19 +* Security: Enhanced security on the campaign block. (CVE-2026-97643)
20 +* Security: Enhanced security for the Donor Dashboard access.
21 +
22 += 4.17.0: September 23rd, 2026 =
23 +* Feature: Added the ability to embed donation forms on any website with a copy-paste snippet from the form builder
24 +* Enhancement: Donation form embeds now show a loading state while the form loads
25 +* Fix: Fixed PHP 8.4 deprecation notices about implicitly nullable parameters
26 +* Fix: Fixed the revenue table index migration adding duplicate indexes when it runs more than once
27 +* Fix: Added additional escaping to the legacy donation form's billing address fields.
28 +* Security: Donors can no longer add unverified email addresses to their own donor record.
29 +* Security: Enhanced security for donations imported from CSV
30 +
31 += 4.16.9: September 16th, 2026 =
32 +* Security: Added additional validation to PayPal Commerce donation processing.
33 +* Security: Added additional sanitization to donor information displayed on public pages.
34 +* Fix: Resolved an issue where resuming a paused Stripe subscription triggered a fatal error.
35 +
36 += 4.16.8.1: September 10th, 2026 =
37 +* Security: Improved validation of the event tickets purchase flow.
38 +* Security: Added additional validation to PayPal Commerce completed-order processing.
39 +* Security: Added additional validation to donor email lookups. Thanks Jakub Herman for responsibly disclosing this issue.
40 +
41 += 4.16.8: September 3rd, 2026 =
42 +* Fix: Fixed a campaign's default donation form appearing unpublished in the form builder.
43 +* Fix: Fixed PHP warnings on the form builder screen when its page is opened without the locale or donation form ID query arguments.
44 +* Fix: Resolved a plugin conflict that prevented donor first and last names from being recorded when the Charitable plugin was active alongside GiveWP.
45 +* Fix: Resolved an issue where the custom amount minimum and maximum also applied to the donation levels and the set donation amount, so a level below the minimum could not be donated. Forms that leave the minimum empty now fall back to the lowest configured amount, and a minimum or maximum with cents is no longer rounded down.
46 +* Security: Removed vulnerable dead code related to legacy donor relinking. (CVE-2026-82676)
47 +* Security: Enhanced security on donor account access. (CVE-2026-82675)
48 +* Tweak: Replaced the axios HTTP client with WordPress core's apiFetch in the donor dashboard, reports, onboarding wizard, and the log and migration list tables, and removed axios from the plugin's JavaScript dependencies.
49 +
50 += 4.16.7.2: August 27th, 2026 =
51 +* Security: Added additional hardening for serialized data handling in the donation flow.
52 +
53 += 4.16.7.1: August 24th, 2026 =
54 +* Security: Added additional validation to PayPal Donations order requests.
55 +
56 += 4.16.7: August 20th, 2026 =
57 +* Security: Hardened donor-account email access authentication.
58 +* Security: Improved validation of the checkout login form.
59 +* Fix: Resolved an issue where paused or failing Stripe Payment Element subscriptions remained stuck when the donor updated their payment method or the subscription was resumed in Stripe.
60 +* Fix: Resolved a conflict where scripts enqueued by other plugins while a donation form was being rendered could stop the form builder design preview and embedded forms from loading.
61 +* Fix: Resolved an issue where editing a page could exhaust the PHP call stack when a theme or plugin filtered post metadata.
62 +* Fix: Activation banner for addons doesn't show when addons are activated from the Unified License Manager
63 +
64 += 4.16.6.1: August 12th, 2026 =
65 +* Security: Added additional validation to PayPal Standard IPN.
66 +
3 67 = 4.16.6: August 6th, 2026 =
4 68 * Tweak: Improved the unified licensing page experience.
5 69 * Security: Added additional validation when handling serialized data during the donation process.
6 70 * Security: Added additional escaping and validation to legacy donor admin screens and the donors REST API.