Changelog
What’s New
New releases, improvements, and updates to Dokan
-

Germanized fields land in the new product editor, and two security patches tighten access to abuse reports and warranty conversations.
Payments
- Fix: Partial refunds via Authorize.Net are no longer cancelled when an admin approves them, so the refund completes as expected.
- Fix: Payment gateway refunds now display the “Auto” refund type label instead of “Manual”, so the refund source is reported accurately.
Privacy and security
- Fix: Restricted abuse-report management to marketplace administrators, so other roles can no longer view or modify reports.
- Fix: Patched a SQL injection vulnerability in the RMA warranty conversation lookup, so the endpoint can no longer be exploited with crafted requests.
Products
- New: The new vendor product editor now supports EU Compliance Fields (Germanized), so vendors selling in EU markets can fill in unit prices, delivery times, and seller terms without switching to the legacy form.
Orders and shipping
- Update: Germanized order withdrawal is now multi-vendor aware, so each vendor can independently confirm or reject the request for their own sub-order.
- Fix: ShipStation order export no longer fails when the order contains fee line items, so all orders sync regardless of extra charges.
Admin tools
- New: The Vendor Support menu in WP Admin now shows a pending-ticket badge, so open tickets are visible at a glance without opening the list.
-

- Fix: Resolved an issue where Apple Pay was not opening inside the Stripe Express Payment Element when using Safari.
- Fix: Improved security in the Geolocation map info windows by safely handling vendor-supplied shop names, titles, and links to prevent stored cross-site scripting.
- Fix: Ensured product add-on groups can only be deleted by the vendor who owns them.
- Fix: Restricted the all-order-logs CSV export to marketplace administrators, ensuring vendor order and earnings data remains private.
-

- Update: Removed the duplicate Tailwind framework from the admin and dashboard stylesheets, making the asset files smaller and cleaner.
- Fix: Resolved an issue where repeated partial refunds failed for PayPal Marketplace orders by using a unique invoice reference for each refund.
- Fix: Improved security in the Live Chat script by safely handling the vendor shop name and email to prevent stored cross-site scripting.
- Fix: Ensured bookable persons can only be removed from booking products owned by the vendor.
-

- New: Added auction product support to the new vendor product editor, allowing vendors to create and edit auction products without using the legacy form.
- Update: The Stripe Express payment method now appears in Block Checkout only when all vendors in the cart have completed their onboarding.
- Fix: Prevented duplicate order notes from being added to single-vendor orders paid through Stripe Express.
- Fix: Improved security in the Booking module by preventing stored cross-site scripting through customer names and email addresses in the Manage Bookings list.
- Fix: Ensured product add-ons can only be edited by the vendor who owns them.
- Fix: Ensured MangoPay account signup, disconnection, and saved card actions can only be performed for the vendor’s own account.
- Fix: Ensured vendors can only update or delete reviews left on their own products.
- Fix: Ensured auction products can only be edited by the vendor who owns them.
- Fix: Ensured ShipStation shipment notifications are only applied to the vendor’s own orders.
-

- New: Added a Clear Dokan Caches tool to the admin Tools page, allowing admins to refresh cached marketplace data with a single click.
- New: The Manage Permissions page now displays the staff member’s name, making it easier for vendors to identify whose permissions they are editing.
- Update: Tax Status and Tax Class fields are now hidden from the vendor product form when tax calculations are disabled, keeping the form cleaner and removing unnecessary options.
- Fix: Ensured that admin-only subscription packs remain completely hidden from vendors, including on the subscription page and during checkout.
- Fix: Fixed a fatal error that could occur when generating a Credit Note while the Subscription module was enabled.
- Fix: Improved security in the Booking module by ensuring bookings and booking resources can only be viewed, edited, or deleted by their rightful owner.
- Fix: Improved security by ensuring vendor delivery time updates can only be applied to the vendor’s own orders.
- Fix: Patched a cross-site scripting (XSS) vulnerability in the Elementor store template preview to improve security.