Version 3.27.1
Fixed
- A cached page could silently cost a visitor their attribution. The
cuft_store_utmcall that writes the UTM and click-id cookies carries a nonce printed into the page HTML, and a page cache can serve that HTML for longer than WordPress keeps a nonce valid (24 hours). Past that point the call was rejected, no cookie was written, and every form submission from that page arrived with no attribution and no error recorded anywhere. The cookies are now written by the page itself, in the format the server already reads, so attribution survives a stale cached page. Verified against a page whose store call returns 403: the cookie is written and the webhook carries the full attribution set.
Security
- The
cuft_store_utmendpoint keeps its nonce check. Removing it would let any third-party site forge attribution cookies for a visitor through the endpoint, and the client-side write closes the cache gap without weakening that.
Installation
Automatic Update
If you already have the plugin installed, it should automatically detect this update. Go to Plugins in your WordPress admin and click Update Now.
Manual Installation
- Download the
choice-uft-v3.27.1.zipfile from the assets below - In WordPress admin, go to Plugins → Add New → Upload Plugin
- Choose the downloaded zip file and click Install Now
- Activate the plugin after installation
Requirements
- WordPress 5.0 or higher
- PHP 7.4 or higher
Support
For issues or questions, please visit: https://github.com/ChoiceOMG/choice-uft/issues