Added Free Trial Ending Reminder email.
Added Login notification email.
Added Login Activity tab to My Account page showing recent logins.
Fixed security issue where with shortcode execution via comment content on user profile.
Fixed: remove 10-per-day limit on renewal and expiration emails.
Fixed XSS in contextual country state field in checkout.
Fixed: Reflected XSS in member directory filters.
Fixed: User meta enumeration via member directory filters.
Fixed: Member directory role filter could list users outside the directory's configured roles.
Fixed: Registration and login form ID could be tampered with to bypass invite codes, CAPTCHA and form-assigned user roles.
Fixed: Brute-force protection plugins not recording failed logins made via ProfilePress login forms.
Fixed: Unauthenticated file upload via non-file custom fields; files from failed registrations are now deleted.
Fixed: Deactivated membership plans could be purchased at checkout.
Fixed: CSRF in edit profile avatar and cover photo removal.
Fixed: Checkout tax could be bypassed by skipping or altering the order review.
Fixed: Retention-only coupons could be applied to new purchases.
Fixed: Comments on protected content are now hidden from users without access.
Fixed: Content protection bypass via REST API and search for "Pages with Template", "Home or Front Page" and "Blog or Posts Page" rules.
Fixed: REST API search bypass of protected content exclusion.
Fixed: Email content saved by users without the unfiltered_html capability is now sanitized.
Fixed: CSV formula injection in membership exports; exports no longer written to the uploads folder.
Fixed: Missing capability checks on admin notice dismissal, login redirect settings and content protection AJAX.
Fixed: AcademyLMS fatal error for paid courses not mapped to a plan.
Fixed: Sensitive Information Exposure via Shortcode Injection via profile fields.
Fixed: Reflected XSS via ppressbillingaddress and filename param
Fixed PHP Warning: Undefined array key "login_remember".
Fixed bug where edit profile form was missing updated user data.
Made usermoderation enabled by default via checkout.
Added inline validation of email address during checkout.
Added LoginGuard to checkout and registration autologin.
Fixed security issue where subscribers could obtain a paid plan without payment via plan change.
Revalidate coupons at calculation time and fixed race condition bug.
Fixed bug with upgrade/downgrade not working after old sub got expired.
Fixed the security issue in the bio frontend user profile.
Scanned and fixed Fable reported security issues.
Fixed fatal error with emogrify.
ppressallowemptypasswordunchanged filter is true by default
Improved security of license upgrader.
Upgraded internal PHP dependencies.
Fixed security issue with shortcode execution on frontend profile data.
Fixed bug with searching users by country name on member directory.
Fixed bug where expiry emails were sent to customers who have resubscribed.
Fixed invisible checked state on form builder field settings checkboxes.
Added Subscription Payment Failed email notification.
Fixed Stripe bug where email change caused checkout failure.
Fixed fatal error when price has a currency symbol or thousands separator on admin order creation.
Fixed security issue of shortcode execution on first and last name profile fields.
Added optional order creation to the Add New Customer screen.
Fixed bug where suppressed email still went out.
Fixed security issue where other file types (exe, msi) could be uploaded outside ProfilePress upload scope.
Improved support for Jetpack/wp.com SSO.
Made the Pay button text translatable.
Added compatibility with Yoast URL Cleanup feature.
Fixed security issue where non-admin user role can be passed as user role.
Added password visibility icons to the password reset handler form fields
Added filters to the test mode notice and checkout username.
Added membership conditions to Elementor display rules.
Added filtering by status to plan listing page.
Fixed avatar distortion on account page.
Fixed bug where plan duplication missed some data.
Fixed bug with form preview resulting to FATAL error.
Fixed XSS in member and profile listing frontend displays.
Improvement: reject Stripe webhooks when Webhook secret is not configured.
Made customer meta labels translatable.
Added warning to Select Role field in form builder if options are empty.
Improved admin UI for WP7
Fixed bug where users can upgrade/downgrade to a plan not authorized for them.
Fixed bug where subscription renewal email is sent when autorenewal is disabled.
Ensure expiration email is sent when active/trialling subscriptions are not auto-renewable.
Added support for specifying subscription status in content protection shortcode
Added ppressrestrictionshortcoderulelatest_only filter.
Added filter for overriding Stripe billing intervals.
Added a filter to allow per-field filename customization.
Added filter for adding custom columns to the subscriptions list table.
Added action hook and filter for customer details metaboxes.
Fixed issue with plan upgrade by wrong user.
Fixed bug where empty subscription records could be created.
Added filter ppressmdmemberdirectoryfiltersexpanded.
Fixed a security issue where a user could cancel another user subscription.
Subscription is now cancel in gateway before deletion.
Security Fix: Arbitrary Shortcode Execution via Checkout Billing Fields.
Added billing address data to customer export.
Added ppressisthirdparty2fa_active filter.
Fixed a likely fatal error on form preview.
Fixed bug where account info data got lost on group checkout refresh.
Fixed bug where checkout overrides previously uploaded files.
Fixed bug where download link requiring logged in users worked for other logged-in users.
Added custom field placeholder support to admin new user email notification.