Woocommerce Bookings icon

Release v3.9.0

Woocommerce Bookings v3.9.0

What's new in v3.9.0

Woocommerce Bookings v3.9.0 was released on . Setup bookable products such as for reservations, services and hires. See the full changelog below and compare with the complete version history.

Release details

Released
5.9 MB
File available

Changelog

Fixed
  • Fixed a fatal error on the product page and when adding to the cart if a person type cost was stored with a currency symbol or other non-numeric characters.
  • Fixed a person type cost stored with a thousands separator or a decimal comma being priced as only the digits before the separator.
  • Fixed a fatal error when a pricing rule was set to divide by an empty or zero amount.
  • Fixed the admin calendar single-day view defaulting to the server (UTC) date instead of the site timezone, which shifted bookings by a day once UTC and the site were on different calendar dates (for example, past 7 PM in UTC-5).
  • Fixed a false "Error while deleting the item" error when permanently deleting bookings on HPOS stores.
  • Prevented manual booking creation from changing orders without edit permission.
  • Prevented team-member updates from changing unauthorized booking products.
  • Fixed a blocking Google Calendar API call being made on every request (front end, REST API, cron, login) when a Google account is connected; the calendar list is now fetched only when the settings form fields are actually used.
  • Restricted booking product template creation to authorized product editors with a valid request nonce.
  • Fixed the "Booking Person Discount" coupon applying a discount 100 times too large at cart and checkout for currencies with zero decimals (for example JPY).
  • Fixed console errors on admin screens when the WooCommerce Tracks object is unavailable.
  • Fixed the date picker calendar availability announcement not being read by screen readers when the calendar opens on focus.
  • Fixed the admin Add Booking screen and reschedule dialog showing times in the merchant's browser timezone instead of the store timezone when "Display visitor's local time" is enabled.
  • Fixed the admin calendar month and schedule views defaulting an out-of-range year to the server (UTC) year instead of the site timezone, so the calendar could open on the wrong year around New Year.
  • Prevented resource REST requests from reading or deleting team members.
  • Enforced global availability permissions for AJAX create, update, and delete requests.
  • Bound booking product exports to the authorized product and global availability permissions.
  • Limited booking order search results to orders the current user can access.
Other
  • Dev - Removed the vulnerable extract-zip package from the development toolchain to resolve a Dependabot security alert.
  • Dev - Restored TLS certificate verification and fail-closed error handling in the release deployment script.
  • Dev - Pinned and checksum-verified the WP-CLI executable used in release builds.
  • Dev - Wired the pull request CI checks required by the trunk branch protection rules (PHP coding standards, @version tag validation).
  • Dev - Aligned AI-agent docs, ignore rules, and npm script aliases with the sibling extensions.
  • Dev - Updated the npm build toolchain to resolve all remaining Dependabot security alerts.
  • Dev - Update the shipped @babel/runtime helpers to resolve a security advisory.
  • Dev - Fixed Markdown documentation lint violations and wired the Markdown docs lint into CI.
  • Dev - Standardized the package license identifier on GPL-3.0-or-later.
  • Dev - Removed the dead lint:md:js script.
  • Dev - Documented the isolated worktree setup for local development.
  • Dev - Stop waiting on networkidle when opening the front-end product page in E2E specs; wait on the date picker's own readiness signal instead.
  • Dev - Enabled TLS certificate verification for translation downloads.
  • Dev - Seed bookable products for E2E specs through the REST API instead of driving the admin product editor.
  • Dev - Suppressed dependency deprecation notices in the PHP unit test suites.
  • Dev - Added a CI check that fails when the plugin's own PHP sources raise compile-time deprecation notices.
  • Dev - Added a pre-commit check that enforces updating the @version tag to x.x.x on modified PHP classes.
  • Dev - Enabled JavaScript linting in CI and fixed source violations.
  • Dev - Migrated the ESLint setup to the flat config format required by ESLint 10, aligning the lint and formatting toolchain with WooCommerce core.
  • Dev - Update wp-coding-standards/wpcs to 3.4.1 (security release) in the phpcs lint tooling.
  • Dev - Allow-listed the dev-only GPLv3 dependency `@woocommerce/e2e-utils-playwright` and wired `check-licenses` into CI.
  • Dev - Update PHPUnit to 9.6.35 to resolve a security advisory in the PHP test toolchain.
  • Dev - Update development npm dependencies to resolve security advisories in the build toolchain.
  • Dev - Update the shipped phpseclib library to resolve security advisories, and move Strauss and QIT CLI to require-dev.
  • Dev - Update the shipped Guzzle libraries and the Symfony YAML development dependency to resolve security advisories.
  • Dev - Enabled CSS linting in CI and fixed source style violations.
  • Dev - Hardened the QIT test workflow: pinned the QIT CLI vers
Added
  • Support for importing accommodation bookings from a CSV file.

Compatibility

Requires WordPress
6.8
Tested up to
7.0
Requires PHP
7.4

Verified safe

Woocommerce Bookings v3.9.0 scanned clean with no security threats detected.

View full scan report