Skip to content

Version 3.27.1

Choose a tag to compare

@github-actions github-actions released this 19 Sep 03:48
· 33 commits to master since this release

Fixed

  • A cached page could silently cost a visitor their attribution. The cuft_store_utm call that writes the UTM and click-id cookies carries a nonce printed into the page HTML, and a page cache can serve that HTML for longer than WordPress keeps a nonce valid (24 hours). Past that point the call was rejected, no cookie was written, and every form submission from that page arrived with no attribution and no error recorded anywhere. The cookies are now written by the page itself, in the format the server already reads, so attribution survives a stale cached page. Verified against a page whose store call returns 403: the cookie is written and the webhook carries the full attribution set.

Security

  • The cuft_store_utm endpoint keeps its nonce check. Removing it would let any third-party site forge attribution cookies for a visitor through the endpoint, and the client-side write closes the cache gap without weakening that.

Installation

Automatic Update

If you already have the plugin installed, it should automatically detect this update. Go to Plugins in your WordPress admin and click Update Now.

Manual Installation

  1. Download the choice-uft-v3.27.1.zip file from the assets below
  2. In WordPress admin, go to Plugins → Add New → Upload Plugin
  3. Choose the downloaded zip file and click Install Now
  4. Activate the plugin after installation

Requirements

  • WordPress 5.0 or higher
  • PHP 7.4 or higher

Support

For issues or questions, please visit: https://github.com/ChoiceOMG/choice-uft/issues