
Two security patches, plus checkout and shipping-rate fixes for carts that never needed shipping in the first place.
Privacy and security
- Fix: Patched a SQL injection vulnerability in the RMA warranty request listing by binding every filter through prepared statements.
- Fix: Restricted the Dokan Lite installer to users who already hold plugin install and activate permissions, so no one can trigger an install from the admin without the rights to do it.
Orders and shipping
- Fix: Carts holding only products that need no shipping now pass through the WooCommerce block checkout instead of stalling, so customers buying downloadable or virtual items can place their order.
- Fix: Vendor shipping now respects WooCommerce’s “Hide shipping rates when free shipping is available” setting, so customers are shown the free option on its own rather than alongside paid rates.