Repository navigation
3.2.8.4 - August 31st, 2026
·
345 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.
Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.
- Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
- Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
- Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
- Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
- Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)