Changelog
What’s New
New releases, improvements, and updates to Dokan
-

- Update: Removed the duplicate Tailwind framework from the admin and dashboard stylesheets, making the asset files smaller and cleaner.
- Fix: Resolved an issue where repeated partial refunds failed for PayPal Marketplace orders by using a unique invoice reference for each refund.
- Fix: Improved security in the Live Chat script by safely handling the vendor shop name and email to prevent stored cross-site scripting.
- Fix: Ensured bookable persons can only be removed from booking products owned by the vendor.
-

- New: Added auction product support to the new vendor product editor, allowing vendors to create and edit auction products without using the legacy form.
- Update: The Stripe Express payment method now appears in Block Checkout only when all vendors in the cart have completed their onboarding.
- Fix: Prevented duplicate order notes from being added to single-vendor orders paid through Stripe Express.
- Fix: Improved security in the Booking module by preventing stored cross-site scripting through customer names and email addresses in the Manage Bookings list.
- Fix: Ensured product add-ons can only be edited by the vendor who owns them.
- Fix: Ensured MangoPay account signup, disconnection, and saved card actions can only be performed for the vendor’s own account.
- Fix: Ensured vendors can only update or delete reviews left on their own products.
- Fix: Ensured auction products can only be edited by the vendor who owns them.
- Fix: Ensured ShipStation shipment notifications are only applied to the vendor’s own orders.
-

- New: Added a Clear Dokan Caches tool to the admin Tools page, allowing admins to refresh cached marketplace data with a single click.
- New: The Manage Permissions page now displays the staff member’s name, making it easier for vendors to identify whose permissions they are editing.
- Update: Tax Status and Tax Class fields are now hidden from the vendor product form when tax calculations are disabled, keeping the form cleaner and removing unnecessary options.
- Fix: Ensured that admin-only subscription packs remain completely hidden from vendors, including on the subscription page and during checkout.
- Fix: Fixed a fatal error that could occur when generating a Credit Note while the Subscription module was enabled.
- Fix: Improved security in the Booking module by ensuring bookings and booking resources can only be viewed, edited, or deleted by their rightful owner.
- Fix: Improved security by ensuring vendor delivery time updates can only be applied to the vendor’s own orders.
- Fix: Patched a cross-site scripting (XSS) vulnerability in the Elementor store template preview to improve security.
-

- Fix: Improved security in the Live Chat (Tawk.to) module by preventing stored XSS attacks through vendor Property IDs and Widget IDs in the storefront chat script.
- Fix: Improved seller-wise shipping package splitting to ensure it works correctly even when the WooCommerce cart is not fully initialized.
- Fix: Improved Commission API category handling so the earning preview in the product editor always displays accurate commission calculations.
- Fix: Ensured vendors can still view their own draft and hidden products in the new dashboard product list when the Request for Quotation module is enabled.
- Fix: Improved the layout of the Product Q&A table in the admin panel by refining column widths for better readability and consistency.
-

- New: Added store pickup support to Delivery Time on Block Checkout. Vendors offering store pickup can now exclude shipping charges, and the order total Updates instantly based on the selected option.
- Update: Migrated admin dashboard list tables to the unified DataViews experience, providing a more consistent interface for tabs, filters, search, and actions across the admin panel.
- Update: Added a “Search by Author” filter to the vendor dashboard reviews page, making it easier to find reviews from specific customers.
- Fix: Improved security by patching an SQL injection vulnerability related to the latitude and longitude parameters used in geolocation queries.
- Fix: Improved security by patching an SQL injection vulnerability related to the orderby parameter in the Request for Quotation list query.
- Fix: Fixed a vendor staff privilege escalation issue in the Update_capabilities REST endpoint to ensure permissions are properly enforced.
- Fix: Prevented Stripe Express transfers from exceeding the original charge amount when admin coupons are applied to an order.
- Fix: Enforced subscription product limits during bulk editing on the vendor dashboard, ensuring vendors cannot exceed their allowed product limit.
- Fix: Loaded AI Image Enhancer assets correctly on the new vendor dashboard layout for product and auction pages.
- Fix: Corrected the “Only X away” free shipping notice so it appears only when free shipping is actually available on the classic checkout page.
- Fix: Improved the product editor by lazy loading attributes, categories, and tags, preventing memory issues on stores with large product catalogues.
