
Fixes across PayPal checkout, shipping zones, and the vendor dashboard, with five security and permission fixes that tighten who can act on orders, refunds, and vendor data.
Payments
- Fix: PayPal Marketplace no longer marks an order as paid when the PayPal capture is declined, and a later genuine payment can still complete the order.
- Fix: The PayPal Marketplace “Standard Button” type is now honored on the WooCommerce checkout block, so the “Place order” button stays visible.
- Privacy and security
- Fix: Patched a stored cross-site scripting vulnerability in Product Q&A answers by sanitizing them on save and on load.
- Fix: Patched a cross-site scripting vulnerability in the legacy admin screens.
- Fix: Restricted marking an order as received to the logged-in customer who owns it.
- Fix: Restricted refund requests so a vendor can only submit them for their own orders.
- Fix: Hardened Printful so a size guide can only be added to the vendor’s own products.
Vendor dashboard
- Fix: The vendor statement report now counts and paginates its entries correctly instead of rendering an empty table.
- Fix: Cleared a React defaultProps warning on the vendor dashboard analytics report tables.
- Orders and shipping
- Fix: Vendor shipping methods now appear only in the shipping zone they belong to, instead of being offered in every zone.
- Fix: Delivery Time slots now display on the block checkout in the site’s 12- or 24-hour time format.
- Performance
- Fix: The Export/Import product listing data now loads only on the vendor dashboard instead of on every front-end page.
Admin tools
Fix: The “Create” and “Cancel” buttons in the Vendor Verification method modal are now aligned and sized consistently, and a double click no longer creates duplicate methods.