توضیحات
Professional frontend dashboard for WooCommerce and multivendor marketplaces. Supports WCFM Marketplace, Dokan, WC Vendors, WC Product Vendors.
تغییرات این نسخه
Below is a record of updates, features, and fixes across all releases.
6.7.28
Updated – 28/06/2026
Security – Fixed an Unauthenticated Authorization Bypass vulnerability that allowed arbitrary reply injection into store inquiries and unsolicited notification emails.
Security – Fixed an Insecure Direct Object Reference (IDOR) vulnerability that allowed authenticated vendors to archive products, toggle featured listings, mark orders complete, and delete inquiries and messages belonging to other vendors.
Enhance – Added developer hooks to add a custom column to the Vendors list (wcfm_vendors_custom_column_header, wcfm_vendors_custom_column_data_after, plus filterable DataTable column config).
Enhance – Added action hooks to the Article manager view (before_wcfm_article_manage_action, after_wcfm_article_manage_action, wcfm_article_manager_featured_image_field_end).
Enhance – Added the wcfm_dashboard_after_limit_stats hook and refreshed the Dashboard welcome box to a responsive layout.
Enhance – WooCommerce 10.9+ compatibility check added
Enhance – WordPress 7.0+ compatibility check added
6.7.27
Updated – 25/04/2026
Enhance – PHP compatibility expanded: now supports versions 7.2–8.4
6.7.26
Updated – 16/03/2026
Security – Fixed an Authenticated IDOR vulnerability allowing unauthorized user deletion. Reported by Supakiad S. (m3ez).
Security – Fixed an Authenticated IDOR vulnerability allowing unauthorized post/product manipulation. Reported by Osvaldo Noe Gonzalez Del R
6.7.28
Updated – 28/06/2026
Security – Fixed an Unauthenticated Authorization Bypass vulnerability that allowed arbitrary reply injection into store inquiries and unsolicited notification emails.
Security – Fixed an Insecure Direct Object Reference (IDOR) vulnerability that allowed authenticated vendors to archive products, toggle featured listings, mark orders complete, and delete inquiries and messages belonging to other vendors.
Enhance – Added developer hooks to add a custom column to the Vendors list (wcfm_vendors_custom_column_header, wcfm_vendors_custom_column_data_after, plus filterable DataTable column config).
Enhance – Added action hooks to the Article manager view (before_wcfm_article_manage_action, after_wcfm_article_manage_action, wcfm_article_manager_featured_image_field_end).
Enhance – Added the wcfm_dashboard_after_limit_stats hook and refreshed the Dashboard welcome box to a responsive layout.
Enhance – WooCommerce 10.9+ compatibility check added
Enhance – WordPress 7.0+ compatibility check added
6.7.27
Updated – 25/04/2026
Enhance – PHP compatibility expanded: now supports versions 7.2–8.4
6.7.26
Updated – 16/03/2026
Security – Fixed an Authenticated IDOR vulnerability allowing unauthorized user deletion. Reported by Supakiad S. (m3ez).
Security – Fixed an Authenticated IDOR vulnerability allowing unauthorized post/product manipulation. Reported by Osvaldo Noe Gonzalez Del R