| @@ -3,14 +3,14 @@ | ||
| 3 | 3 | Donate link: https://bdthemes.com/ |
| 4 | 4 | Tags: elementor addons, post grid, post carousel, post slider, blog layout |
| 5 | 5 | Requires at least: 6.8 |
| 6 | 6 | Tested up to: 7.1 |
| 7 | -Stable tag: 4.5.4 | |
| 7 | +Stable tag: 4.5.6 | |
| 8 | 8 | Requires PHP: 7.0 |
| 9 | 9 | License: GPL3 |
| 10 | 10 | License URI: https://www.gnu.org/licenses/gpl-3.0.html |
| 11 | 11 | Elementor requires at least: 4.0.0 |
| 12 | -Elementor tested up to: 4.2.4 | |
| 12 | +Elementor tested up to: 4.3.4 | |
| 13 | 13 | |
| 14 | 14 | Build WordPress blog, magazine, news, archive and single-post layouts with Elementor post grid, carousel, slider and list widgets. |
| 15 | 15 | |
| 16 | 16 | == Description == |
| @@ -298,8 +298,9 @@ | ||
| 298 | 298 | 1. **BdThemes news feed** (`https://bdthemes.com/feed`) - This optional dashboard widget is disabled by default. After an administrator enables “BdThemes News & Updates” in Ultimate Post Kit > Other Settings, it requests the public RSS feed while an administrator views the WordPress dashboard. No personal or site data is sent. Service provider: [BdThemes Terms](https://bdthemes.com/terms-conditions/) and [Privacy Policy](https://bdthemes.com/privacy-policy/). |
| 299 | 299 | 2. **Mailchimp API** - The Newsletter widget uses the site owner's configured Mailchimp account and list. A subscriber's email address and optional name are sent to Mailchimp when the visitor submits the form. Service provider: [Mailchimp Terms](https://mailchimp.com/legal/terms/) and [Intuit Privacy Statement](https://www.intuit.com/privacy/statement/). |
| 300 | 300 | 3. **Social share-count APIs** - When a supported share-count option is enabled, the widget requests public share counts from the relevant network for the current page URL. The page URL is sent to the selected service when the widget is rendered. Services can include Facebook, Pinterest, Buffer, Tumblr, WhatsApp and Mail.ru. |
| 301 | 301 | 4. **Vimeo oEmbed** (`https://vimeo.com/api/oembed.json`) - Video widgets use this service to retrieve the dimensions or thumbnail of a Vimeo video supplied by the site owner. The public Vimeo URL is sent to Vimeo when that content is rendered. Service provider: [Vimeo Terms](https://vimeo.com/legal/) and [Privacy Policy](https://vimeo.com/legal/privacy). |
| 302 | +5. **BdThemes newsletter** (`https://marketing.sigmative.com`) - Used only if an administrator opts in to the BdThemes newsletter on the setup wizard's welcome screen. The opt-in checkbox is unticked by default. If it is ticked when the administrator clicks "Get Started", the email address entered there, together with the first and last name from that administrator's WordPress profile, is sent to subscribe them to the newsletter. Nothing is sent when the box is left unticked. Service provider: [BdThemes Terms](https://bdthemes.com/terms-conditions/) and [Privacy Policy](https://bdthemes.com/privacy-policy/). | |
| 302 | 303 | |
| 303 | 304 | = Source Code and Build Process = |
| 304 | 305 | |
| 305 | 306 | The plugin is not obfuscated. Human-readable source for minified or compiled assets is bundled in the `src` directory, including JavaScript, controls and LESS/CSS sources. Compiled files in `assets` are generated with Grunt. |
| @@ -309,8 +310,17 @@ | ||
| 309 | 310 | |
| 310 | 311 | The build configuration is included in `gruntfile.js` and `package.json`. Bundled third-party libraries retain their upstream license and version comments. |
| 311 | 312 | |
| 312 | 313 | == Changelog == |
| 314 | + | |
| 315 | += 4.5.6 [6th October 2026] = | |
| 316 | + | |
| 317 | +* Fixed: Security issue in the Author widget where the Social Links setting was used as a user field name without being checked against the available options | |
| 318 | +* Updated: Security improved | |
| 319 | + | |
| 320 | += 4.5.5 [24th September 2026] = | |
| 321 | + | |
| 322 | +* Updated: System improved | |
| 313 | 323 | |
| 314 | 324 | = 4.5.4 [13th September 2026] = |
| 315 | 325 | |
| 316 | 326 | * Updated: Security improved |