v5.1.2 | September 17, 2026

A security-focused release that restricts review, attribute, and variation changes to the product’s owner and keeps the Stripe secret key out of vendor records, with fixes to admin-screen counts and storefront performance.

Privacy and security
  • Fix: Stopped the Stripe secret API key from being saved to vendor account meta, and cleaned up records that already contained it.
  • Fix: Hardened product review moderation so reviews can only be moderated or deleted by the vendor who owns the product, including through bulk actions.
  • Fix: Hardened product editing so attributes can only be changed by an administrator or the vendor who owns the product.
  • Fix: Restricted removing product variations to the vendor who owns the product.
  • Fix: Restricted saving product variations to the vendor who owns the product.
  • Fix: Hardened Vendor Verification so new verification requests are always created as pending until an administrator reviews them.
Products
  • Fix: Restored the “Search similar products in this marketplace” panel on the new product editor, and limited product cloning to published products only.
Performance
  • Fix: Rebuilt the Geolocation category filter as a lightweight component so storefront pages no longer load the full WooCommerce Admin bundle, and corrected category names containing HTML entities.
Admin tools
  • Fix: The admin Subscriptions list now includes vendors whose selling is disabled, so their subscription packs can still be managed and cancelled.
  • Fix: The “All” count on the Abuse Reports and Product Advertising screens now matches the rows shown, since orphaned entries are kept out of both lists.
  • Fix: The AI Assist image “Model” setting now defaults to an image-capable model, so the dropdown no longer renders blank.