Skip to content

3.3.9.2 - August 31st, 2026

Latest

Choose a tag to compare

@sc0ttkclark sc0ttkclark released this 31 Aug 17:40
· 9 commits to main since this release
Immutable release. Only release title and notes can be modified.
3.3.9.2
139d67e

This is a major security hardening release covering multiple areas of the plugin. We recommend updating as soon as possible.

Additional releases with these security fixes have been backported to each major version of Pods from Pods 2.7 and above to make it easy to update.

  • Security: Restricted display callbacks to an explicit allow list of safe functions, with optional customized additions requiring a dedicated prefix. Added detection and admin notices when disallowed display callbacks are used on a site. (Jakub Herman, @sc0ttkclark)
  • Security: Refactored form nonce handling to harden against submission misuse. (Jakub Herman, @sc0ttkclark)
  • Security: Hardened shortcode and block logic against output and query misuse. (Wordfence PRISM - Wordfence, @sc0ttkclark)
  • Security: Fixed post_status handling in the last security release so it only applies to user-provided inputs (not Pods internal logic). (@sc0ttkclark)
  • Security: Added anonymous form post handling back that had unintentionally been disabled in the last security release. (@sc0ttkclark)