- **update:** Guided vendors through verification when "Verified Only" selling is enabled, replacing the generic notice with clear next steps and a link to the verification page.
- **fix:** Linked quote-converted orders to their vendor so they appear in the vendor's Orders list, and split multi-vendor quotes into per-vendor sub-orders.
- **fix:** Rendered vendor verification method help text with its formatting on the React vendor dashboard, matching the legacy dashboard.
- **fix:** Made vendor verification method Edit and Delete controls always visible and fixed silent edit and delete failures.
- **fix:** Stopped the booking product list from showing a subscription limit notice while Product Subscription is disabled, and honored the vendor's selling status.
- **new:** Added an "Allow ordering from non-connected sellers" setting to Stripe Express, holding the vendor's share for payout once they complete onboarding.
- **fix:** Fixed WordPress 7.1 compatibility for the Booking module stylesheet and the Dokan Shortcode block.
- **fix:** Fixed WooCommerce block checkout blocking carts that contain only no-shipping products.
- **fix:** Made vendor shipping honor WooCommerce's "hide rates when free shipping is available" setting.
- **fix:** Patched a SQL injection in the RMA warranty-request listing by binding all filters with prepared statements.
- **fix:** Required plugin install and activate capabilities in the Dokan Lite installer AJAX handler.
- **new:** Added a pending-ticket badge to the admin Vendor Support menu so open tickets are visible at a glance.
- **new:** Added Germanized EU compliance field support to the new vendor product editor so vendors no longer need the legacy form.
- **update:** Made Germanized order withdrawal multi-vendor aware so each vendor can confirm or reject the request for their own sub-order.
- **fix:** Fixed ShipStation order export failing for orders that contain fee line items.
- **fix:** Prevented partial refunds via Authorize.Net from being cancelled when approved by an admin.
- **fix:** Showed the "Auto" refund type label for payment gateway refunds instead of "Manual".
- **fix:** Restricted abuse-report management to marketplace administrators.
- **fix:** Patched a SQL injection in the RMA warranty conversation lookup by binding the request ID as an integer.
- **fix:** Fixed Apple Pay not opening inside the Stripe Express Payment Element on Safari.
- **fix:** Prevented stored cross-site scripting in the Geolocation map info windows by escaping vendor-supplied shop names, titles, and links.
- **fix:** Ensured product add-on groups can only be deleted by their owner.
- **fix:** Restricted the all-order-logs CSV export to marketplace administrators so vendor orders and earnings stay private.
- **update:** Removed a duplicated copy of the Tailwind framework from admin and dashboard stylesheets for smaller, cleaner asset bundles.
- **fix:** Fixed repeat partial refunds failing on PayPal Marketplace orders by sending a unique invoice reference for each refund.
- **fix:** Prevented stored cross-site scripting in the Live Chat script by escaping the vendor shop name and email.
- **fix:** Ensured bookable persons can only be removed from the vendor's own booking products.
- **new:** Added auction product support to the new vendor product editor so vendors can create and edit auctions without the legacy form.
- **update:** Showed the Stripe Express payment method in block checkout only when every vendor in the cart has completed onboarding.
- **fix:** Prevented duplicate order notes on single-vendor orders paid via Stripe Express.
- **fix:** Prevented stored cross-site scripting in the Booking module's Manage Bookings list by escaping customer names and emails.
- **fix:** Ensured Product Add-ons can only be edited by their owner.
- **fix:** Ensured MangoPay account signup, disconnection, and saved-card actions apply only to the vendor's own account.
- **fix:** Ensured vendors can only update or delete reviews on their own products.
- **fix:** Ensured auction products can only be edited by their owner.
- **fix:** Ensured ShipStation shipment notifications apply only to the vendor's own orders.
- **new:** Added a "Clear Dokan Caches" tool on the admin Tools page so stale marketplace data can be refreshed in one click.
- **new:** Showed the staff member's name on the Manage Permissions page so vendors always know whose access they are editing.
- **update:** Hid Tax Status and Tax Class on the vendor product form when tax calculations are turned off, removing fields that had no effect.
- **fix:** Kept admin-only subscription packs fully hidden from vendors, including on the subscription page and at checkout.
- **fix:** Fixed a fatal error when generating a Credit Note while the Subscription module is active.
- **fix:** Hardened the Booking module so bookings and booking resources can only be viewed, changed, or deleted by their rightful owner.
- **fix:** Hardened vendor delivery time updates so they can only be saved against a vendor's own orders.
- **fix:** Patched a cross-site scripting vulnerability in the Elementor store template preview.
- **fix:** Prevented stored XSS in the Live Chat (Tawk.to) module by escaping vendor Property and Widget IDs in the storefront chat script.
- **fix:** Improved seller-wise shipping package splitting when the WooCommerce cart is not yet ready.
- **fix:** Improved Commission API category handling so the product editor's earning preview stays accurate.
- **fix:** Ensured vendor's own draft and hidden products remain visible in the new dashboard product list when the Request for Quotation module is active.
- **fix:** Refined the admin Product Q&A table column widths for a clearer, more consistent layout.