v5.1.3 | September 24, 2026

Fixes across PayPal checkout, shipping zones, and the vendor dashboard, with five security and permission fixes that tighten who can act on orders, refunds, and vendor data.

Payments
  • Fix: PayPal Marketplace no longer marks an order as paid when the PayPal capture is declined, and a later genuine payment can still complete the order.
  • Fix: The PayPal Marketplace “Standard Button” type is now honored on the WooCommerce checkout block, so the “Place order” button stays visible.
  • Privacy and security
  • Fix: Patched a stored cross-site scripting vulnerability in Product Q&A answers by sanitizing them on save and on load.
  • Fix: Patched a cross-site scripting vulnerability in the legacy admin screens.
  • Fix: Restricted marking an order as received to the logged-in customer who owns it.
  • Fix: Restricted refund requests so a vendor can only submit them for their own orders.
  • Fix: Hardened Printful so a size guide can only be added to the vendor’s own products.
Vendor dashboard
  • Fix: The vendor statement report now counts and paginates its entries correctly instead of rendering an empty table.
  • Fix: Cleared a React defaultProps warning on the vendor dashboard analytics report tables.
  • Orders and shipping
  • Fix: Vendor shipping methods now appear only in the shipping zone they belong to, instead of being offered in every zone.
  • Fix: Delivery Time slots now display on the block checkout in the site’s 12- or 24-hour time format.
  • Performance
  • Fix: The Export/Import product listing data now loads only on the vendor dashboard instead of on every front-end page.
Admin tools

Fix: The “Create” and “Cancel” buttons in the Vendor Verification method modal are now aligned and sized consistently, and a double click no longer creates duplicate methods.