WooCommerce 4.2.1 Security and Fix Release

We’ve shipped a new release containing some security improvements for SelectWoo as well as other minor bugfixes. Here is the changelog for the release:

**WooCommerce**
* Security - Escape HTML in SelectWoo.
**WooCommerce Admin 1.2.4**
* Tweak: reduce asset filename length and remove tilde characters. #4535
* Fix: RTL stylesheet loading for split code chunks. #4542

We highly recommend updating WooCommerce to this version as soon as possible.

Download the latest release of WooCommerce here or visit Dashboard → Updates to update the plugin from your WordPress admin screen.


As usual, if you spot any other issues in the WooCommerce core, please log them in detail on GitHub. Found a security issue? Please submit a report via HackerOne.


Keep yourself in the loop!

This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form


7 responses to “WooCommerce 4.2.1 Security and Fix Release”

  1. Updated my sites from 4.2, thx for the fixes!!

    1. Peter Fabian Avatar
      Peter Fabian

      Hi,

      Thanks for reaching out! I see your problem has been solved in the support forum by our Happiness engineers, so hope all is working fine now.

  2. sjsbazarpk Avatar
    sjsbazarpk

    In the latest version, I have problem. My website was working fine and I don’t know what happened. The Woocommerce REST API endpoints of Products and Orders is not working. I am unable to access in Woocommerce mobile app as well as the app of my store.

    1. Peter Fabian Avatar
      Peter Fabian

      Hi,

      It’s a bit difficult to tell without further information, but please try the general troubleshooting steps from this document: https://docs.woocommerce.com/document/woocommerce-self-service-guide/

      Also, you can try checking your PHP error log, if you know where to find it, maybe it would reveal the source of your problems.

    2. Facing same issue. Did you find any solution?

Leave a Reply

Your email address will not be published. Required fields are marked *