Skip to content

Releases: pods-framework/pods

3.3.9.2 - August 31st, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 31 Aug 17:40
Immutable release. Only release title and notes can be modified.
3.3.9.2
139d67e

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

3.2.8.4 - August 31st, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 31 Aug 17:39
Immutable release. Only release title and notes can be modified.
3.2.8.4
f349066

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

3.1.4.3 - August 31st, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 31 Aug 17:39
Immutable release. Only release title and notes can be modified.
3.1.4.3
9eee663

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

3.0.10.5 - August 31st, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 31 Aug 17:38
Immutable release. Only release title and notes can be modified.
3.0.10.5
2c9ce7e

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

2.9.19.5 - August 31st, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 31 Aug 17:38
Immutable release. Only release title and notes can be modified.
2.9.19.5
8bfc87f

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

2.8.23.5 - August 31st, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 31 Aug 17:37
Immutable release. Only release title and notes can be modified.
2.8.23.5
414d523

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

2.7.31.4 - August 31st, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 31 Aug 17:36
Immutable release. Only release title and notes can be modified.
2.7.31.4
8dcdd2f

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)

3.3.9.1 - August 14th, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 14 Aug 15:07
Immutable release. Only release title and notes can be modified.
4675b51

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.

  • Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
  • Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
  • Security: Improved safety when handling previously stored data. (@sc0ttkclark)
  • Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
  • Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
  • Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Hardening improvements to file and media handling. (@sc0ttkclark)
  • Security: Additional safeguards for file and template handling. (@sc0ttkclark)
  • Security: Improved handling of displayed content. (@sc0ttkclark)
  • Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
  • Security: Additional validation for imported content. (@sc0ttkclark)
  • Security: Improved handling of content based on user permissions. (@sc0ttkclark)
  • Security: Updated bundled third-party JavaScript dependencies. (@sc0ttkclark)
  • Security: Added a filter to optionally restrict access to the REST API documentation endpoint, which remains public by default. (@sc0ttkclark)
  • Security: Additional automated test coverage for the changes in this release. (@sc0ttkclark)

3.2.8.3 - August 14th, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 14 Aug 15:12
Immutable release. Only release title and notes can be modified.
3.2.8.3
0c1042f

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.

  • Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
  • Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
  • Security: Improved safety when handling previously stored data. (@sc0ttkclark)
  • Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
  • Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
  • Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Hardening improvements to file and media handling. (@sc0ttkclark)
  • Security: Additional safeguards for file and template handling. (@sc0ttkclark)
  • Security: Improved handling of displayed content. (@sc0ttkclark)
  • Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
  • Security: Additional validation for imported content. (@sc0ttkclark)
  • Security: Improved handling of content based on user permissions. (@sc0ttkclark)

3.1.4.2 - August 14th, 2026

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 14 Aug 15:14
Immutable release. Only release title and notes can be modified.
3.1.4.2
f032b22

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above.

  • Security: Further restrictions on error handling and fallbacks. (Nhien Pham @nhienit - GalaxyOne, @thevietronin - GalaxyOne, @sc0ttkclark)
  • Security: General hardening improvements to how data queries are built and validated. (HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Additional restrictions on how certain values are processed when displayed. (@sc0ttkclark)
  • Security: Improved safety when handling previously stored data. (@sc0ttkclark)
  • Security: Removed a legacy request-handling path that is no longer needed. (HaoNH @haoit, @sc0ttkclark)
  • Security: Tightened access requirements for certain background requests. (HaoNH @haoit, @sc0ttkclark)
  • Security: Improved consistency and enforcement of access and validation checks. (Youness HFA from AGBS Pentest Team @YounesHfa, HaoNH @haoit, @onebitious, @sc0ttkclark)
  • Security: Hardening improvements to file and media handling. (@sc0ttkclark)
  • Security: Additional safeguards for file and template handling. (@sc0ttkclark)
  • Security: Improved handling of displayed content. (@sc0ttkclark)
  • Security: Added extra verification for admin forms and actions. (@sc0ttkclark)
  • Security: Additional validation for imported content. (@sc0ttkclark)
  • Security: Improved handling of content based on user permissions. (@sc0ttkclark)
Sponsor
SponsoredKunjungi sekarang
Promo