Changelog

What’s New

New releases, improvements, and updates to Dokan

  • Two security patches, plus checkout and shipping-rate fixes for carts that never needed shipping in the first place.

    Privacy and security
    • Fix: Patched a SQL injection vulnerability in the RMA warranty request listing by binding every filter through prepared statements.
    • Fix: Restricted the Dokan Lite installer to users who already hold plugin install and activate permissions, so no one can trigger an install from the admin without the rights to do it.
    Orders and shipping
    • Fix: Carts holding only products that need no shipping now pass through the WooCommerce block checkout instead of stalling, so customers buying downloadable or virtual items can place their order.
    • Fix: Vendor shipping now respects WooCommerce’s “Hide shipping rates when free shipping is available” setting, so customers are shown the free option on its own rather than alongside paid rates.
  • Germanized fields land in the new product editor, and two security patches tighten access to abuse reports and warranty conversations.

    Payments
    • Fix: Partial refunds via Authorize.Net are no longer cancelled when an admin approves them, so the refund completes as expected.
    • Fix: Payment gateway refunds now display the “Auto” refund type label instead of “Manual”, so the refund source is reported accurately.
    Privacy and security
    • Fix: Restricted abuse-report management to marketplace administrators, so other roles can no longer view or modify reports.
    • Fix: Patched a SQL injection vulnerability in the RMA warranty conversation lookup, so the endpoint can no longer be exploited with crafted requests.
    Products
    • New: The new vendor product editor now supports EU Compliance Fields (Germanized), so vendors selling in EU markets can fill in unit prices, delivery times, and seller terms without switching to the legacy form.
    Orders and shipping
    • Update: Germanized order withdrawal is now multi-vendor aware, so each vendor can independently confirm or reject the request for their own sub-order.
    • Fix: ShipStation order export no longer fails when the order contains fee line items, so all orders sync regardless of extra charges.
    Admin tools
    • New: The Vendor Support menu in WP Admin now shows a pending-ticket badge, so open tickets are visible at a glance without opening the list.

    • Fix: Resolved an issue where Apple Pay was not opening inside the Stripe Express Payment Element when using Safari.
    • Fix: Improved security in the Geolocation map info windows by safely handling vendor-supplied shop names, titles, and links to prevent stored cross-site scripting.
    • Fix: Ensured product add-on groups can only be deleted by the vendor who owns them.
    • Fix: Restricted the all-order-logs CSV export to marketplace administrators, ensuring vendor order and earnings data remains private.
    • Update: Removed the duplicate Tailwind framework from the admin and dashboard stylesheets, making the asset files smaller and cleaner.
    • Fix: Resolved an issue where repeated partial refunds failed for PayPal Marketplace orders by using a unique invoice reference for each refund.
    • Fix: Improved security in the Live Chat script by safely handling the vendor shop name and email to prevent stored cross-site scripting.
    • Fix: Ensured bookable persons can only be removed from booking products owned by the vendor.
    • New: Added auction product support to the new vendor product editor, allowing vendors to create and edit auction products without using the legacy form.
    • Update: The Stripe Express payment method now appears in Block Checkout only when all vendors in the cart have completed their onboarding.
    • Fix: Prevented duplicate order notes from being added to single-vendor orders paid through Stripe Express.
    • Fix: Improved security in the Booking module by preventing stored cross-site scripting through customer names and email addresses in the Manage Bookings list.
    • Fix: Ensured product add-ons can only be edited by the vendor who owns them.
    • Fix: Ensured MangoPay account signup, disconnection, and saved card actions can only be performed for the vendor’s own account.
    • Fix: Ensured vendors can only update or delete reviews left on their own products.
    • Fix: Ensured auction products can only be edited by the vendor who owns them.
    • Fix: Ensured ShipStation shipment notifications are only applied to the vendor’s own orders.