WooCommerce 8.1.1 is now available for download. It contains a security fix, and we therefore recommend updating at your earliest possible convenience.
What’s new?
- Security: an ajax endpoint used within the order editor was returning user meta data. This was previously fixed in our 7.0.1 release, but was regrettably reintroduced. More details are available in this dev advisory. #40221
- We resolved a problem leading to the duplication of order meta data, potentially impacting merchants who have enabled HPOS (High-Performance Order Storage) alongside compatibility mode (sync). #40148
You can download the latest release of WooCommerce here or visit Dashboard → Updates to update the plugin from your WordPress admin screen.
If you spot issues in WooCommerce core, please log them in detail on GitHub. Found a security issue? Please submit a report via HackerOne.
Leave a Reply