Changelogs
Changelog
-
Update:
- LearnDash – Mark a quiz complete for the user – Added an “All quizzes” option to mark all quizzes in a course, lesson, or topic #4616
Fixed:
- Core – Prevented PHP deprecation notices when reading an empty license key #4590
- Formidable – A form is submitted with a specific value in a specific field – Prevented the trigger from firing on incomplete or abandoned entries #4601
- Hardened token processing across multiple integrations against unsafe serialized data #4598
- LearnDash – Multiple actions – Restored “All” option handling #4607
- MemberPress – Prevented an undefined array key warning when parsing Corporate Account tokens #4609
- Memberium for Keap, GravityKit, RafflePress, Code Snippets – Fixed demand-driven loading of helpers and AJAX handlers #4613
- Paid Memberships Pro – Fixed the admin membership level assignment trigger not firing due to an invalid capability check #4605
- Webhooks – Prevented PHP deprecation notices when incoming webhook payloads contain null values #4580
Under the hood:
- Core – Removed deprecated WP Bitly integration #4604
-
Fixed:
- LearnDash – Restored “Any” option handling across multiple triggers and dropdowns. #8514
- Memberium for Keap and SureCart – Fixed triggers and actions failing to run on frontend requests. #8523
- Uncanny Agent and Page Builder – Improved feature availability during temporary connection issues. #8501
-
Updated:
- Fluent Forms – Added value and label tokens for choice fields, making selections more flexible. #8455
Fixed:
- Formidable Forms – Restored the shared helpers instance to keep things running smoothly. #8518
- Formidable Forms – Submission triggers now ignore incomplete and abandoned entries. #8509
- Hardened PeepSo and related token processing against unsafe serialized data. #8505
- LearnDash – A user has completed X% of a course – Fixed “0f” to correctly display “% of”. #8516
- Page Builder – Removed the unnecessary “Reload editor” option from the Uncanny Agent notice. #8506
- Uncanny Agent – Strengthened security for legacy admin-AJAX requests. #8499
- WordPress – Create a post – Parent posts now appear in the dropdown instead of playing hide-and-seek. #8491
Under the hood:
- Core – Removed unnecessary license API response logging for cleaner logs. #8495
-
New Plugin Integrations:
- All-in-One WP Migration #4276
- FluentBoards #4227
- FluentCart #4239
- Really Simple Security #4291
New Triggers:
- All-in-One WP Migration – A site restore fails #4304
- All-in-One WP Migration – A site restore is completed #4305
- FluentBoards – A board’s title or description is updated #4228
- FluentBoards – A subtask is added to a task on a board #4229
- FluentCart – A user’s license for a product expires #4240
- FluentCart – A user’s license for a product is disabled #4242
- FluentCart – A user’s license for a product is renewed #4241
- FluentCart – A user’s license for a product is upgraded #4243
New Actions:
- All-in-One WP Migration – Remove the label from a backup file #4303
- FluentBoards – Delete a task #4230
- FluentBoards – Remove a user from a task #4231
New Conditions:
- FluentBoards – A task has a label #4237
- FluentBoards – A task has a priority #4232
- FluentBoards – A task has a status #4233
- FluentBoards – A task is assigned to a user #4236
- FluentBoards – A task is in a stage #4235
- FluentBoards – A task is on a board #4234
- FluentCart – A customer’s lifetime value meets a condition #4247
- FluentCart – A customer’s purchase count meets a condition #4246
- FluentCart – An order contains a product #4245
- FluentCart – An order’s total meets a condition #4244
- Really Simple Security – The user has/does not have two-factor authentication enabled #4350
Update:
- Webhooks – Receive data from a webhook – Updated to the latest framework. #4529
Fixed:
- Gravity Forms – Multiple triggers – Form title/ID tokens resolve incorrectly or empty. #4557
- Gravity Forms – Multiple triggers – List row and Entry deleted triggers were not firing after the switch to on-demand loading. #4563
-
New Plugin Integrations:
- All-in-One WP Migration #7539
- FluentBoards #7479
- FluentCart #7494
- Really Simple Security #7555
New Triggers:
- All-in-One WP Migration – A backup file is deleted #7580
- All-in-One WP Migration – A site backup fails #7581
- All-in-One WP Migration – A site backup is created #7563
- FluentBoards – A board is created #7486
- FluentBoards – A comment is added to a task on a board #7483
- FluentBoards – A label is added to or removed from a task on a board #7485
- FluentBoards – A task is created on a board #7480
- FluentBoards – A task on a board is completed or reopened #7481
- FluentBoards – A task on a board’s due date is set or changed #7484
- FluentBoards – A user is assigned to a task on a board #7482
- FluentBoards – A user is unassigned from a task on a board #7487
- FluentCart – A user’s order changes to a status #7497
- FluentCart – A user’s order for a product is paid #7495
- FluentCart – A user’s subscription changes to a status #7501
- FluentCart – A user’s subscription to a product is activated #7496
- FluentCart – A user’s subscription to a product is cancelled #7498
- FluentCart – A user’s subscription to a product is renewed #7499
- Really Simple Security – A vulnerability scan is completed #7639
New Actions:
- All-in-One WP Migration – Delete a backup file #7579
- All-in-One WP Migration – Set a backup file’s label to a specific value #7578
- FluentBoards – Add a comment to a task #7493
- FluentBoards – Add a user to a board #7490
- FluentBoards – Assign a user to a task #7491
- FluentBoards – Create a board #7489
- FluentBoards – Create a task on a board #7488
- FluentBoards – Update a task’s properties #7492
- FluentCart – Add a note to an order #7505
- FluentCart – Cancel a subscription #7504
- FluentCart – Set an order to a status #7503
Fixed:
- App Integrations – Fixed webhook keys being reset when integration settings were saved. #8438
- Core – Custom trigger and action label fields not loading. #8416
- Core – Log action resend drops per-request credential scope. #8413
- Discord – Settings – Server disconnect leaves stale connected status. #8422
- Facebook – Settings – Connected account avatar 403s after the stored CDN URL expires. #8424
- Gravity Forms – Added consolidated checkbox field tokens and fixed Form title and ID tokens in submission triggers. #8397
- HubSpot – Create/Update a contact – Enumeration fields drop token values matching option labels. #8418
- Page Builder – Fixed styling issues with reusable sections added by users or Agents. #8434
- Page Builder – Improved Save Draft reliability and canvas consistency. #8433
- Page Builder – Improved reusable section previews, copying, and style persistence. #8432
- Recipe Builder – Fixed sentence pills displaying outdated values after fields were updated. #8435
- Recipe Builder – Fixed the editor failing to load or save recipes with actions using custom values. #8391
Under the hood:
- Improved in-plugin notifications. #8177
-
7.5.1.1 [2026-08-15]
Fixed:
- Page Builder – Preserved the last published page content when Automator is deactivated or deleted, and improved file system safety checks. #8385
- Recipe UI – Condition field values lost on save, reverting to the first dropdown option. #8366
- Setup wizard – Fixed an issue with the “Build my first page” button failing to create a page. #8379
-
New Feature:
- Uncanny Agent – Lite users now get free starter usage of Uncanny Agent
Updated:
- Setup wizard – Improved the setup flow, navigation, security, and interface for a smoother onboarding experience. #8332
Fixed:
- Uncanny Agent – Page Builder – Improved editor reliability, including saving, Undo and Redo, canvas refreshes, and working across multiple browser tabs. #8370
- Uncanny Agent – Page Builder – Fixed issues with publishing, downloads, reusable sections, dynamic content, and design style changes. #8370
- Uncanny Agent – Page Builder – Improved compatibility with different database configurations, screen sizes, and third-party extensions. #8370
- Uncanny Agent – Page Builder – Improved error handling and recovery to prevent unexpected failures from interrupting Page Builder operations. #8370
-
Fixed:
- Uncanny Agent – Page Builder – Fixed a fatal error on some sites when themes did not provide a current post ID for singular page requests. #8348
- Uncanny Agent – Fixed a Sodium compatibility fatal error on hosts without the native Sodium extension. #8348
-
Fixed:
- Uncanny Agent – Page Builder – Improved validation of page, section, canvas, reusable-part, and other request identifiers to prevent malformed data from causing errors or targeting unintended content.
- Uncanny Agent – Page Builder – Hardened WordPress hooks, administration callbacks, meta boxes, editor requests, and cleanup operations against missing or unexpected data.
- Uncanny Agent – Page Builder – Improved rendering safeguards to prevent invalid dynamic or conditional content, unintended published content, and stale page data from affecting output.
- Uncanny Agent – Page Builder – Improved validation and reliability of import, export, shell analysis, and static export operations.
- Uncanny Agent – Page Builder – Added permission checks for canvas deletion and improved handling of sensitive error information.
- Uncanny Agent – Page Builder – Improved compatibility and error handling on sites with missing server extensions or unexpected request data.
-
Fixed:
- Uncanny Agent – Fixed an issue where the Agent could disappear from the WordPress admin until the Automator settings page was visited. #8341
- Uncanny Agent – Improved recovery when WordPress security keys change to prevent the Agent from becoming unavailable. #8341
Under the hood:
- Core – Improved transient cleanup to prevent stale cached data after plugin deactivation. #8287
- Uncanny Agent – Added Site Health diagnostics to help administrators identify Agent configuration issues. #8341
- Uncanny Agent – Improved site identity, verification, and protection for information exchanged with the Agent. #8341
-
New Plugin Integration:
- Site Kit by Google #4266
New Conditions:
- Site Kit by Google – A module is active #4265
- Site Kit by Google – Site Kit setup is complete #4264
- Site Kit by Google – The user is connected to Site Kit #4263
Fixed:
- BuddyBoss & BuddyPress – Notification actions – Fixed an issue where actions remained stuck at “Not completed” and notifications were not displayed. #4523
- Forminator – Fixed an issue where Time field tokens rendered as “10:30 am” instead of “10 – 30 am”. #4515
- LearnDash – Send a certificate – Fixed an issue where custom CSS was printed as text in generated PDFs instead of being applied. #4513
-
New Feature:
- Uncanny Page Builder – Create and refine beautiful pages through conversation with Uncanny Agent (requires an Uncanny Automator Pro AI + Automation plan) #8330
New Integration:
- Site Kit by Google #7528
New Triggers:
- Site Kit by Google – A module is activated #7526
- Site Kit by Google – A module is deactivated #7525
New Actions:
- Site Kit by Google – Activate a module #7524
- Site Kit by Google – Deactivate a module #7523
Fixed:
- Closures – Restored the “Redirect when all triggers are completed” checkbox for all recipes. #8285
- Forminator – Fixed an issue where Time field tokens rendered as “10:30 am” instead of “10 – 30 am”. #8284
Under the hood:
- Core – Fixed an issue where the “Immediately delete log entries when recipes are completed” setting never purged logs. #8294
-
Updated:
- Kadence – Modernized the integration to use the latest framework. #8228
- PrettyLinks – Modernized the integration with unified support for Pretty Links v3 and v4. #8219
Fixed:
- AI settings – Closed an arbitrary code execution path by ensuring the provider settings save handler no longer executes request-supplied callbacks. #8273
- Discord and Asana credentials – Replaced XOR encryption with authenticated AES-256-GCM to provide stronger protection for stored credentials. #8274
- Facebook Groups – Repaired the nonce check on the app install verification handler to help prevent cross-site request forgery. #8272
- Kadence – All triggers – Fixed an issue where forms would not fire recipes when gated loading was enabled. #8228
- Recipe logs – Long-running multi-trigger recipes that became stuck are now correctly terminated by the recovery process. #8227
- Setup wizard – Added a capability check to prevent lower-privileged users from changing the wizard’s connection status. #8271
- Translations – Fixed an issue where Recipe Builder strings were not loading correctly in Spanish. #7392
Under the hood:
- Core – Added automatic retries for app actions that fail before reaching the server, improving reliability without risking duplicate actions. #8225
- Core – Missing classmap files no longer result in PHP errors when the fallback autoloader is used. #8175
- Core – Internal OAuth tokens are now encrypted for improved security. #8230
- Core – Trigger hooks fired during raw shutdown callbacks are now properly captured and delivered. #8221
-
Fixed:
- Automatic login link – Hardened validation of automatic login links. #4507
- BuddyBoss – Trigger – A user registers with a specific value in a specific field – Fixed an issue where the trigger did not fire correctly in some cases. #4484
- Incoming webhooks – Hardened the processing of data received from webhooks. #4506
- Kadence – A user submits a form with a specific value in a specific field – Fixed an issue where the trigger would not fire when gated loading was enabled. #4489
- LearnDash – Group triggers – Fixed an issue where the ID, URL, image, and leader tokens returned
1or were empty when “Any” was selected. #4482 - Loop filters – Added a permission check to the loop token dropdown. #4509
- Tutor LMS – Enroll a user in a course – Fixed an issue where the action stopped working after the latest Tutor LMS update. #4481
- WordPress – Set post meta – Hardened token value handling in the action. #4508
- WP Job Manager – Trigger – Fixed an issue where the Job owner ID and Candidate ID tokens always returned empty values. #4487
-
New Plugin Integrations:
- Beaver Builder #4224
- Redirection #4274
- WP Activity Log #4261
- Wordfence Security #4250
New Triggers:
- Beaver Builder – A form is submitted #4225
- Beaver Builder – A subscribe form is submitted #4226
- Wordfence Security – A password reset is requested #4252
- Wordfence Security – An attack rate increase is detected #4251
New Actions:
- Advanced Coupons – Reset a user’s store credit to zero #3777
- Redirection – Create a redirect #4273
- Redirection – Delete a redirect #4272
- Redirection – Disable a redirect #4270
- Redirection – Enable a redirect #4271
New Conditions:
- Redirection – A redirect exists for a URL #4269
- WP Activity Log – An event’s severity meets a condition #4259
- Wordfence Security – An IP address is blocked #4253
- Wordfence Security – An IP address is whitelisted #4254
- Wordfence Security – The user has two-factor authentication enabled #4256
Update:
- WordPress, ACF, Meta Box & JetEngine – Improved meta trigger performance by skipping unnecessary checks when no recipe needs them. #4442
Fixed:
- BuddyPress – Activity stream actions no longer cause a PHP error on sites without BuddyBoss. #4466
- LearnDash – A user completes a group’s courses – Restored the “Number of times” option. #4471
- LearnDash – A user submits an essay for a quiz – Fixed legacy options that prevented the trigger configuration from opening. #4473
Under the hood:
- Core – Added a safeguard for licenses missing the “expires” property. #4469
- Divi – Updated to the latest framework. #4222
- Software licensing updater – Updated the package to keep licensing checks running smoothly. #4475
-
New App Integration:
- GoTo Meeting #7993
New Plugin Integrations:
- Beaver Builder #7476
- Redirection #7533
- WP Activity Log #7522
- WP Fastest Cache #7534
- Wordfence Security #7506
New Triggers:
- Beaver Builder – A user submits a contact form #7477
- Beaver Builder – A user submits a subscribe form #7478
- Redirection – A 404 error is logged #7532
- Redirection – A redirect in a group is matched #7529
- Redirection – A redirect is created by the URL monitor #7530
- Redirection – A redirect is deleted #7531
- WP Activity Log – A failed login is logged #7520
- WP Activity Log – An event for an object type is logged #7518
- WP Activity Log – An event is logged #7521
- WP Activity Log – An event of a type is logged #7517
- WP Activity Log – An event with a severity is logged #7519
- WP Fastest Cache – All cache is cleared #7535
- Wordfence Security – A blocking rule is deleted #7513
- Wordfence Security – A login with a breached password is blocked #7509
- Wordfence Security – A user activates two-factor authentication #7510
- Wordfence Security – A user deactivates two-factor authentication #7511
- Wordfence Security – An IP is blocked/throttled #7508
- Wordfence Security – An IP is locked out #7507
- Wordfence Security – An admin/non-admin user logs in #7512
New Actions:
- GoTo Meeting – Create a meeting #7994
- GoTo Meeting – Delete a meeting #7995
- GoTo Training – Add an attendee #7996
- GoTo Training – Remove an attendee #7997
- WP Fastest Cache – Purge all caches #7537
- WP Fastest Cache – Purge the cache for a post #7538
- Wordfence Security – Block an IP address #7514
- Wordfence Security – Remove an IP block #7515
- Wordfence Security – Remove an IP lockout #7516
Fixed:
- Automator review – Added capability and nonce checks to the review settings handler, keeping unauthorized option changes firmly off the guest list. #8159
- Bluesky – Protected post embed URL requests against SSRF, including redirects that tried to take the scenic route somewhere unsafe. #8157
- Credits notifications – Added a capability check so lower-privileged users can no longer dismiss site-wide credit notices. #8161
- Facebook Lead Ads – Added payload validation and optional authorization controls to webhooks, giving unexpected requests a proper ID check. #8155
- Gravity Forms – Blank List fields no longer stop recipes during form submission. Empty lists can now pass quietly without causing a scene. #8019
- HubSpot, Brevo, Constant Contact – Deprecated actions – Prevented deprecated actions from loading when demand-driven loading is enabled. Retired means retired. #8035
- LearnDash – Create a group / Make the user the leader of a group – Fixed legacy option data that prevented the action configuration from opening. #8170
- LearnDash – Restored the missing loopable tokens to the Token Loop, where they belong. #8021
- LearnDash – Triggers – Restored the “Number of times” option for affected triggers. The counter is back on duty. #8168
- Modern Events Calendar – Added authorization and nonce checks to event and ticket AJAX handlers for safer request handling. #8163
- Recipe log – Secured the “View preview” popup against stored XSS by rendering its HTML inside a sandboxed iframe. The preview now stays in its lane. #8165
- WordPress – Restored the missing loopable tokens to the Token Loop. #8028
Security Fixes:
- Google Contacts & Mautic – Added capability and nonce checks to option fetchers, ensuring only authorized requests get through. CVE-2026-15025 #8152
- Forminator and related token reads – Hardened token handling against PHP Object Injection. CVE-2026-15008 #8150
- Loopable integrations (CSV/XML/JSON) – Blocked private-network requests in loopable URL fetchers and hardened token-alias migrations against object injection. #8151
Under the hood:
- Core – Corrected app-credit limits for legacy Pro and Lifetime licenses. The numbers now behave as their licenses intended. #8138
- Divi – Modernized the integrations using the new framework, giving the foundations a well-earned refresh. #7458
- Uncanny Agent – Database select tool – Secured WHERE and JOIN handling with validated predicates and prepared values. Database queries now follow a stricter dress code. #8014
- Uncanny Agent – Secured component requests with encrypted license credentials, request binding, and fail-closed handling. When verification fails, the door stays closed. #8174
-
New Feature:
- Status > Tools – “Resend App Actions” tool to find and bulk resend failed app actions from one place. #8012
Updated:
- App Actions – Increased the default outgoing request timeout to better support longer-running app responses. #8009
- Kit – Removed the unsupported OAuth connection flow and now support V4 connections by API key only. #8006
- Stripe – Improved product and price dropdown performance in the recipe builder with cached remote loading and refresh support. #7999
- Stripe – Product refunded trigger now correctly respects the selected price instead of firing for every refunded product. #7999
Fixed:
- ActiveCampaign – Fixed an issue where custom fields could be omitted from the Add a contact action when field definitions needed to be refreshed. #7949
- App Actions – Fixed an issue where resending a logged app action could trigger a PHP error on some sites. #8011
- App Actions – Fixed an issue where successful app action responses could be incorrectly reported as “Failed with status code: 200”. #8010
- Google Contacts – Fixed an issue where the Create a contact action could include internal Automator action metadata in outgoing API requests. #8004
- Recipe UI – Fixed an issue where select fields in the recipe builder could stop rendering when another plugin loaded a conflicting Select2 library. #8001
Under the Hood:
- Recipe Templates – Fixed an issue where the requirements sidebar could stretch past the window edge and cut off text. #7941
- Trigger Engine – Improved handling of high-frequency WordPress meta hooks to reduce unnecessary trigger checks and loopback requests. #7929
-
Added:
- Recipe Logs – Added a recipe status filter to the admin logs page. #4458
Fixed:
- LearnDash – Fixed an issue where email-based actions were missing the rich-text body editor and could strip HTML when saved. #4462
- User Selector – Fixed an issue where actions could still run for existing users when “Do nothing” was selected. #4456
-
Updated:
- Google Sheets, Calendar and Gemini icons updated #7798
Fixed:
- Hardened WP Event Manager, FluentCRM, Gravity Forms, and WS Form Lite trigger token handling against PHP Object Injection by safely handling user-submitted values #7939
- Instagram – Catch
Throwableinstead of onlyExceptionwhen publishing posts #7940
-
Fixed:
- bbPress & BuddyBoss – A guest replies to a topic – PHP Object Injection via unserialized guest token meta #4436
- Events Manager – Resolved a PHP error that could occur when loading registration-related triggers in certain version-mismatched environments #4455
- Hardened Forminator, Gravity Forms, WS Form, and Plugin Actions trigger token handling against PHP Object Injection by safely handling user-submitted values #4449
- Scheduled actions – Added a recovery tool for delayed and scheduled actions orphaned by a cleanup issue affecting some sites running Pro 7.2.0 through 7.3.0.6 #4453
- Scheduled actions – Orphan-hash cleanup deletes data for still-pending actions on high-volume sites, so they silently never run #4438
- Thrive Apprentice – Grant user access to a product – No longer reports successful completion when access is not granted #4435
-
Fixed:
- Events Manager – Resolved a PHP error that could occur when loading registration-related triggers in certain version-mismatched environments #7912
- LearnDash – Quiz triggers now correctly resolve quiz score, question-and-answer, and related quiz result tokens #7908
- Recipe logs – Delayed and scheduled actions now display the correct scheduled execution dates. #7895
- WPForms, MailPoet, and FunnelKit (Autonami) – Improved protection against PHP Object Injection when storing user-submitted trigger token values #7921
-
- Maintenance: Updated internal version and refreshed plugin package.
-
Fixed:
- LearnDash – Course enroll/unenroll/expiry triggers now return the correct Course ID token value #4426
- Loop filters – WordPress, WordPress-MU and LearnDash – Some loop filters no longer get silently skipped under demand-driven loading #4428
-
Fixed:
- Mailchimp – Credential mapping issue on some older sites now resolved #7885
- Mailchimp – Create and send a campaign – Fails when ‘To name’ is empty #7881
- WP Job Manager – A user applies for a job – Fixed an issue where some tokens may not parse #7875
- WordPress – A post in a taxonomy is published & A user publishes a post in a taxonomy – Only one recipe fires per post due to dedup keyed by code #7883
Under the Hood:
- Multiple integrations – Correct invalid singular
supports_tokendefinitions to pluralsupports_tokens#7831 - Normalize UTM tags on in-plugin links #7880
-
Fixed:
- Magic Button/Link – Post ID & Post title tokens return 0/empty after lazy-load migration #4419
- WordPress – A user updates a post in a specific status & A user updates a post with a specific term in a specific taxonomy – Only one recipe fires per post due to dedup keyed by code #4423
Under the Hood:
- Multiple integrations – Correct invalid singular
supports_tokendefinitions to pluralsupports_tokens#4410 - Normalize UTM tags on in-plugin links #4422