Changelog

Version History

Here you can find out what has changed and have a complete overview of the version history. The changes are divided into different categories.

3.1.8.9

28. August 2026

[Email Designer] Security hardening for email template rendering

This release closes a security issue in how the Email Designer renders email templates. Updating to 3.1.8.9 is strongly recommended. Full details will follow after the coordinated disclosure.
fix

3.1.8.8

31. July 2026

Fixed an unauthenticated arbitrary password reset in the Pro Forms "Reset User Password" action

A published Pro Form using the Reset User Password action in Update mode could be used by an unauthenticated visitor to set the password of any account. The action now verifies ownership: a logged-in user changing their own password, a valid WordPress reset key, an account created by the same submission, or a user the visitor is allowed to edit. Reported by moonge via WPScan.
fix

[Pro Forms] Hardened the user and post actions against anonymous misuse

Update User, Update User Meta and Update/Delete Post now require that the submission owns the target (or that the site owner explicitly scoped the post type), instead of trusting an ID or email taken from a form field.
fix

[API Query Builder] Loading conditions now apply on archive pages (WooCommerce shop, CPT/date archives, search, 404)

fix

[Pro Forms] Fixed an "Undefined array key submitButtonConditionsRelation" warning on submit button conditions

fix

[Pro Forms] bricksforge_send_mail() now runs inside Custom Actions (REST requests)

fix

[General] External Files CSS: element styles are no longer lost when a post is saved outside the builder

fix

[Split Text] Restored word wrapping and overflow clip/reveal after the GSAP SplitText 3.15 update; property-less Lines actions run again

fix

[General] Fixed BRFPANEL being localised twice on the frontend (removed a duplicated ~107 KB inline payload)

fix

3.1.8.7

14. July 2026

Security Fix

Fixed a privilege escalation issue in the Pro Forms submission handling (CVE-2026-14956), reported to us through responsible disclosure.
fix

[Admin Pages] Hide an Admin Page from the WP admin sidebar Register an Admin Page without adding it to the sidebar — still reachable by direct link.

new

[Admin Pages] Added BRICKSFORGE_ADMIN_PAGE_CANVAS constant and bricksforge_is_admin_page_canvas() helper

new

[Submissions] CSV exports now respect column visibility and order

improvement

[Pro Forms] MailerPress status default now respects double opt-in

fix

[Pro Forms] Compatibility Fix for plugin "Payment Plugins for Stripe WooCommerce"

fix

Create Your
Free Playground

Test Bricksforge 7 days for free – as often you want!