15 versions
Paid Memberships Pro history.
Every release of Paid Memberships Pro is archived here with its changelog, file size, and security scan result. Use the archive to roll back to a stable release or audit what changed between updates.
14 of 15 releases scanned clean
v3.8.6Latest
September 8, 20264.4 MBScanned
Added
- Changed the "Edit Membership" button on the Edit Member memberships panel to "Update Membership" to make it clear that it saves the level change. #3781 (@flintfromthebasement)
- The password visibility toggle now shows only the eye icon in the log in widget and on narrow screens so the field label and the toggle no longer wrap into each other. #3769 (@kimcoleman)
- Wisdom tracking data now reports whether the site is running on PMPro Hosting. #3770 (@dparker1005)
Fixed
- Stripe Connect sites now refresh the platform publishable key from Paid Memberships Pro instead of using the key saved during the initial connection forever, so onsite checkout keeps working after the platform key is rotated. #3791 (@flintfromthebasement)
- Liquid tags that the visual email template editor wrapped in paragraph tags no longer produce empty or unbalanced paragraphs in sent emails. #3782 (@dparker1005)
- The 3.8.4 upgrade script no longer fires order update hooks (e.g. Zapier) for every order whose Stripe transaction IDs were recovered. #3790 (@dparker1005)
- Fixed the Stripe Connect environment lookup in `has_connect_credentials()` so that Site Health checks the credentials for the active gateway environment, and avoided a PHP notice after a failed Stripe Connect disconnect response. #3777 (@flintfromthebasement)
- The "Error:" prefix in Stripe Connect failure notices now renders in bold instead of as literal HTML. #3774 (@flintfromthebasement)
August 6, 20264.4 MBScanned
Added
- Added new `--pmpro--btn--border-radius`, `--pmpro--btn--top-bottom-padding`, and `--pmpro--btn--left-right-padding` CSS variables so that button styles can be customized separately from other elements that share the base variables. #3747 (@RachelRVasquez)
Fixed
- Fixed an issue where Stripe Checkout orders paid with delayed notification payment methods such as SEPA Direct Debit could be completed without their subscription and payment transaction IDs, which prevented membership cancellations from being sent to Stripe. An upgrade script now recovers the missing IDs for previously affected orders. #3745 (@dparker1005)
- Fixed an issue where a user field could be shown at checkout even though its field group was hidden from checkout if the field overrode the group's profile visibility setting. #3744 (@dparker1005)
- Fixed an issue where duplicate recurring scheduled tasks, such as those inherited from a cloned or migrated database, would run simultaneously indefinitely. Duplicate chains are now cancelled automatically, keeping the earliest scheduled task. #3746 (@dalemugford)
July 31, 20264.3 MBScanned
Added
- Site Health now detects the PMPro SMTP Add On as the site's email sending service when a connector is configured. #3729 (@dparker1005)
- Added translator comments to localized strings containing placeholders so translators have context for each variable. #3730 (@jahidhasan018)
- The discount code lookup in `PMPro_Discount_Code::save()` now uses `$wpdb->prepare()`. #3734 (@andrewlimaza)
Fixed
- Multi-value user fields (multiselect, select2, and grouped checkboxes) now display correctly when their values were imported from a CSV file as a comma-separated string. #3742 (@flintfromthebasement)
- Fixed a fatal error that could occur when returning from an offsite gateway if the checkout data was missing from the order meta. #3741 (@dparker1005)
- Fixed PMPro core and Add Ons never auto-updating in the background because the update hooks were only registered on `admin_init`, which does not fire during WP-Cron where automatic updates run. #3738 (@dalemugford)
- Set `new_version` on `no_update` entries so up-to-date Add Ons no longer trigger an undefined property warning in WP-CLI and other consumers of the plugin update transient. #3738 (@dalemugford)
- The bulk user delete confirmation screen now counts membership history for every selected user instead of only the first. #3733 (@jahidhasan018)
- The level group selection message is no longer shown on the Membership Levels page for groups that contain only one level. #3731 (@jahidhasan018)
v3.8.2Unavailable
July 14, 20264.4 MBScanned
Other
- SECURITY: Restored sanitization of user field values on save, which had been inactive since v3.4. #3726 (@dparker1005)
- SECURITY: The Authorize.net Silent Post handler now requires Authorize.net API credentials to be configured on the site. #3724 (@dparker1005)
Fixed
- Read-only user fields are no longer saved on form submission and are now escaped when displayed. This also fixes read-only checkbox and select field values being erased on profile update. #3726 (@dparker1005)
- Fixed broken CSV exports when an exported value contained a quotation mark. #3716 (@dwanjuki)
- Fixed checkout failures that could occur when the matching Stripe price had been archived in the Stripe dashboard. #3717 (@flintfromthebasement)
- Fixed an issue where users with the `pmpro_reports` capability could not view email content in the Email Log popup. #3718 (@dwanjuki)
v3.8.1Unavailable
June 29, 20264.4 MBScanned
Added
- Added a new `style` attribute to the `[pmpro_checkout_button]` shortcode to render it as a link or a button, and improved its styling. #3708 (@kimcoleman)
- Improved the HTML validity and accessibility of frontend forms and pages, including fixing duplicate `id` attributes and invalid fieldset/legend markup. #3707 (@kimcoleman)
- Added a new `pmpro_restrictable_taxonomies` filter, allowing Add Ons to register custom taxonomies whose terms can be restricted by membership level from the term edit screen. #3704 (@kimcoleman)
Fixed
- Fixed a fatal error on the Membership Billing page when a subscription's gateway object could not be loaded. #3706 (@kimcoleman)
- Fixed the Members List CSV export so the exporting admin is no longer incorrectly included when exporting filtered or searched results. #3711 (@andrewlimaza)
- Fixed a 404 error when viewing email log details in the modal on sites using Plain permalinks. #3712 (@dwanjuki)
- Fixed select fields overflowing the viewport on small screens. #3705 (@kimcoleman)
- Saving a membership level no longer clears term restrictions, such as tag restrictions, that were set from the term edit screen. #3704 (@kimcoleman)
- Restricted posts are now correctly hidden from searches and archives when a term's ID and term taxonomy ID differ. #3704 (@kimcoleman)
v3.8Unavailable
June 15, 20264.3 MBScanned
Added
- Upgraded the email template editor to the standard WordPress visual/text editor with built-in Liquid syntax autocomplete for variables, tags, and filters. #3695 (@dparker1005)
- Added a new `[pmpro_membership_level]` shortcode for displaying membership level details. #3087 (@kimcoleman)
- Added Divi 5 compatibility for PMPro module-level restrictions and no-access message handling. #3620 (@JarrydLong)
- Added a new `level_group_id` email template variable to every email template class that exposes `membership_id`. #3684 (@kimcoleman)
- Allowed shortcodes in the account page message. #3682 (@kimcoleman)
- Removed the misleading "Advanced Settings" hint from the no-access message controls. #3699 (@dparker1005)
- Clarified the user field meta key hint on the user field settings page. #3698 (@kimwhite)
- Added an Add On icon for the MemberPress Migration Toolkit. (@kimcoleman)
Fixed
- FIX/ENHANCEMENT: Now hiding the recurring trial settings on membership level and discount code edit pages when the active gateway doesn't support recurring trials. #3628 (@dparker1005)
- FIX/ENHANCEMENT: Added a fallback for email logging when SMTP plugins (e.g. Gravity SMTP) bypass the `wp_mail_succeeded` and `wp_mail_failed` actions. #3697 (@andrewlimaza)
- Cleaned up orphaned membership level relationships when a level is deleted. #3693 (@dparker1005)
- No longer shows the membership confirmation message when the order has not been confirmed. #3682 (@kimcoleman)
- Fixed a fatal error on the Membership Billing page for logged-out requests. #3694 (@flintfromthebasement)
- Fixed the Orders list table appearing blank on mobile by setting the order code as the default primary column. #3696 (@dparker1005)
- Cleared stale card information when a recovered Stripe payment uses a non-card payment method. #3703 (@dparker1005)
Improved
- Removed unused `pmpro_userfields_get_group` and `pmpro_userfields_get_field` AJAX handlers. #3672 (@dparker1005)
Removed
- Deprecated the credit card expiring email template. #3688 (@dparker1005)
- The Membership Billing page no longer writes `pmpro_b*` user meta on save, and the email field has been removed from that page. #3668 (@dparker1005)
May 28, 20264.3 MBScanned
Fixed
- FIX/ENHANCEMENT: Skip the `pmpro_visit` cookie when `WP_CACHE` is active so page caches like Surge, Cloudflare, Varnish, and WP Super Cache aren't bypassed on anonymous front-end requests. Added a new `pmpro_set_visit_cookie` filter to override the default behavior. #3690 (@flintfromthebasement)
- Fixed Stripe recurring orders silently saving `tax = 0` after the Stripe API version bump by deriving tax from `invoice->total_excluding_tax` instead of the deprecated `invoice->tax`. #3685 (@dwanjuki)
- Fixed Site Health reporting a false-positive Action Scheduler library conflict on Windows hosts by normalizing the library path before the conflict check. #3687 (@dparker1005)
- Fixed button icons no longer being inline in the WordPress 7.0 admin and the "Show" label floating to the right of the levels dropdown on the Members List screen. #3689 (@RachelRVasquez)
v3.7.2Unavailable
May 2, 20264.3 MBScanned
Other
- SECURITY: Tightened ownership check in the `/pmpro/v1/order` REST permission callback to bail early for anonymous requests, require a non-empty order ID, and use a strict integer comparison. #3643 (@flintfromthebasement)
- SECURITY: Scoped the `/pmpro/v1/quick_search` users meta lookups to custom profile fields by skipping internal WP/plugin meta keys. Added the `pmpro_rest_api_quick_search_meta_key_blocklist` filter so sites can extend the blocklist. #3644 (@flintfromthebasement)
- SECURITY: Fixed a non-functional capability guard in `PMPro_Field_Group::save_fields()` where a literal string comparison made the `current_user_can( 'edit_user' )` check unreachable. #3645 (@flintfromthebasement)
Added
- Reworked the Email Settings and Security Settings admin pages to detect the active email sending method and security provider, surface that information in Site Health, recognize PMPro Max as a provider, and remove the legacy built-in SendWP integration. #3656 (@kimcoleman)
- Renamed the Builder and Plus Add Ons to Max throughout the admin and labeled all paid Add Ons under the new Premium license tier. #3650 (@dparker1005)
- Added the new PayPal Gateway Add On to the Payment Gateway settings page, surfacing it as "Enabled (via Add On)" when active as a secondary gateway. #3657 (@dparker1005)
- Added new filters for avatar upload location and render location to support multisite installations. #3648 (@kimcoleman)
- Updated the Design Settings page link to a direct URL so tracking parameters work without a redirect. #3625 (@kimwhite)
- Added/updated Add On icons including a new MailerLite icon for an upcoming Add On. #3627, #3652 (@kimcoleman)
Fixed
- FIX/ENHANCEMENT: Fixed three bugs that caused member CSV export downloads to return 403/404: deferred export record cleanup until after the file is served, extended download token TTL to 7 days and hardened the URL builder when no token is available, and prevented zero-record exports from creating a ghost "complete" state. Introduced the `pmpro_restricted_file_served` action and buffered handler output to avoid corrupting the response. #3637 (@dalemugford)
- Fixed a deprecated `pmpro_changeMembershipLevel()` call when deleting a WP user. #3660 (@kimwhite)
- Fixed deprecation notices in `pmpro_cleanPhone()` when the phone value is `null`. #3654 (@dwanjuki)
- Fixed the All Levels member export producing duplicate rows and omitting members with higher user IDs in large exports. #3632 (@flintfromthebasement)
- Fixed the `checkbox_grouped` field input not receiving the correct CSS selectors. #3646 (@kimcoleman)
- Skipped content visibility controls for unsupported blocks in widget editors to prevent JS errors. #3653 (@dwanjuki)
v3.7.1Unavailable
April 21, 20264.4 MBScanned
Fixed
- Fixed some admin pages not saving due to POST redirect in list table referer cleanup. #3624 (@kimcoleman)
- Fixed PHP 8.1 deprecation warnings in restricted files functions on Windows servers with misconfigured upload directories. #3623 (@flintfromthebasement)
Removed
- Deprecated the PayPal Express gateway. PayPal is retiring the NVP/SOAP API that PayPal Express relies on. A new PayPal integration is coming soon. #3622 (@dparker1005)
- Renamed the Website Payments Pro gateway slug from `paypal` to `paypalwpp` to free the `paypal` slug for the upcoming PayPal REST API Add On. #3622 (@dparker1005)
Why archive
Sometimes the latest release isn't the one you need. The archive lets you pin Paid Memberships Pro to a known-good version, or roll back while a bug is investigated. Every release stays scanned and reachable.