Journal des modifications
Historique des versions
Qu'en est-il des correctifs de sécurité ? Nous prenons cela très au sérieux et les publions régulièrement.
- MCP server: MCP access for selected users - the administrator grants MCP to named users, each gets a personal key and works under his own WordPress account and rights; two-factor connection is always on for them.
- MCP server: permission map for MCP (hook woobe_mcp_permissions) - full / read / none per area of the shop, per user.
- MCP server: every report answer says in one line that its figures come from WooCommerce Analytics and, while Analytics imports orders on a schedule, how many newer orders are not in them yet.
- NEW: History shows who made each change and whether it was done by hand or through the AI assistant; administrators see and can roll back everyone's history, other users see only their own.
- Change: History filter "by Author" replaced by "Who made the change" with an extra "by hand / through AI agent" filter (administrators only).
- Change: stock quantity, weight and dimension filters - an empty "from" now means no lower limit, so "to" alone also finds negative stock (it started at 0), as through the MCP server.
- MCP server fix: GET request to the MCP endpoint caused a PHP fatal error.
- MCP server fix: MCP rollback left an empty bulk entry in History.
- MCP server fix: woobe_find_products refuses a filter key it cannot use, or a value in another shape, and says why; before, such a condition was ignored and the whole catalogue was selected.
- MCP server fix: number ranges of the product filter work as the tool description says - from included, to excluded, a missing end open, from equal to to exactly that value; a stock range 0 to 0, a stock "from" alone or a weight of 0 selected the whole catalogue.
- MCP server fix: whole_catalogue in the answer of woobe_find_products is true whenever the selection holds every product.
- MCP server fix: arguments of the wrong type are refused with a readable error instead of PHP warnings or an HTTP 500; a text such as "maybe" no longer counts as a confirmation.
- MCP server fix: several product finds in one request carried each other's conditions.
- MCP server fix: a product read of an id that is no product caused a PHP fatal error.
- MCP server fix: gallery, upsells, cross-sells and grouped products given as a list of ids were emptied.
- MCP server fix: creating a product with a SKU already in use now says the SKU was left empty.
- MCP server fix: creating a product with a category name or a missing category id now warns instead of saying nothing.
- MCP server fix: an order for a customer that does not exist is refused.
- MCP server fix: the margin report logged a WooCommerce notice per product when Cost of Goods Sold was off.
- MCP server fix: a unix timestamp given for a date field (the sale dates) was stored as 1970 - it is read as the day it falls on in the shop's time zone, and woobe_list_fields names the formats a date field takes.
- MCP server fix: the bulk preview checked each operation of a run against the stored values, so a sale price set together with a new regular price showed as refused; it follows the run's operations in order now, as the apply does.
- MCP server fix: creating a variable product refused a list with the same variation twice; both were created and checkout sold only one.
- MCP server fix: adding variations with the same combination listed twice dropped the second one without a word; it is now refused.
- MCP server: the product creation preview now warns about a SKU already in use and about attribute values that look like existing ones (S next to Small), before anything is written.
- MCP server fix: the "product with this name already exists" warning no longer counts products in the trash.
- MCP server fix: the bulk preview showed a new stock for variations that sell from their parent's shared stock and for variable products without stock management, although nothing is written on them; they are now shown unchanged and named in the stock_not_tracked warning.
- Fix: History rows written in the same second could disappear from the list.
- Fix: PHP warnings for shop managers when the field visibility settings had never been saved.
- Fix: History pagination jumped several pages after the list was reloaded.
- Fix: the rollback of a bulk stock edit put a product that does not track its stock - a variable product whose variations hold the stock - under stock management, at 0 and out of stock.
- Fix: History revert of a gallery, upsells, cross-sells or grouped products change emptied the field.
- Fix: History revert of a sale date deleted the sale schedule.
- Fix: History list pages after the second could not be reached after the page size was changed.
- Fix: sale price filter with only "from" found nothing; PHP warnings for a price or stock range with one end.
- Fix: a stock quantity range or a product URL filter that matched no product selected every product.
- Fix: stock quantity filter with only "from" filled in selected every product (with "from" 0, only a stock of 0); an empty "to" now means no upper limit, as for the regular price.
- Fix: weight, length, width and height filters with only "from" filled in found nothing; an empty "to" now means no upper limit.
- Fix: the "Menu order from" filter found nothing.
- Fix: History revert of a stock management switch left the stock status WooCommerce had derived from it (for example out of stock); the status comes back with it.
- Fix: a bulk price edit on a selection with variable products wrote a hidden price onto the parents, which no rollback removed; the parents are left alone - their prices live on the variations -, the rollback of such an earlier edit removes the leftover, and through the MCP server a price edit on variable products only is refused, as it would write nothing.
- Fix: weight, length, width and height filters from 0 (or exactly 0) found products whose value was left empty; an empty value is no longer part of any range.
- Fix: a stock of 0 entered on a variable product that does not track stock switched stock management on for it, and every variation without a stock of its own went out of stock; the revert did not bring them back. The value is now left alone, as any other value already was - the stock of a variable product is set on its variations.
- Fix: a stock of 0 entered on a variation that sells from its parent's shared stock detached it from the shared stock with a stock of its own, and the revert did not attach it again. The shared stock is changed on the parent.
- Fix: switching "Manage stock" off let WooCommerce clear the stock quantity, backorders and low stock threshold, and switching it back on left the product at an empty stock and out of stock. The values are now kept and come back when stock management is switched on again in BEAR, and a History revert of the switch restores the quantity as well.
- Fix: PHP warnings when editing the description of a variation.
- NEW: German, French, Italian and Spanish translations of the plugin interface.
- Security: hardening of the MCP server and the bulk editor. Updating is strongly recommended. Thanks to the WordPress.org Plugin Review Team and Patchstack for responsible disclosure.
- MCP server: now off by default and has to be switched on in the plugin settings. Without the MCP key it answers nothing at all.
- MCP server: new optional MCP two-factor connection, off by default. With it on, the MCP key alone is not enough: every AI assistant session also needs a token that the shop administrator confirms in the plugin settings, and the session closes by itself after an hour without use.
- MCP server: an AI assistant can now create products - simple, variable with attributes and variations, external and grouped - with a preview before anything is written. Products are created as drafts and can be published from the chat with one command.
- MCP server: an AI assistant can now work with product images - the media library, the featured image, the gallery and import from a link. It can also give the owner a one-time upload page, valid for 15 minutes and needing no login, where photos are dragged from the computer straight into the media library and onto the product.
- MCP server: an AI assistant can now fill a development shop with generated products - up to 5000, with guided questions, written items for small batches or a vocabulary for large ones, unique names and SKUs, written in portions.
- MCP server: an AI assistant can now create categories, tags, brands and other terms, and attributes together with their values. Non-Latin names are supported.
- MCP server: an AI assistant can now manage variations of existing products - add and remove variations, add or remove an attribute axis, set the default choices, and spot missing, duplicate and "any" variations.
- MCP server: an AI assistant can now work with the orders themselves, not only their figures - a filtered order list, a full order card with address and items, top customers, status changes for several orders at once, notes, refunds with confirmation, and manual orders, including in another currency with the FOX currency switcher.
- MCP server: an AI assistant can now manage coupons - create, edit, trash and restore them, with a preview of what the customer will get.
- MCP server: an AI assistant can now move products to the trash and restore them, export a selection to CSV with a download link, and run WooCommerce maintenance tasks such as clearing transients.
- MCP server: an AI assistant can now build reports across the whole catalogue without selecting products first - best sellers, stock velocity, dead stock and margin.
- MCP server: the sales summary an AI assistant gets now includes refunds for the period.
- MCP server: when an AI assistant puts a product into a subcategory, its parent categories are added as well - on every way of writing, from creating a product to a bulk edit - so the product shows up where customers expect it.
- MCP server: bulk edits can append taxonomy terms instead of replacing them.
- MCP server: before a bulk edit, the AI assistant is warned when replacing attribute values would leave variations that customers can no longer choose.
- MCP server: bulk edit previews show term names instead of ids, and for "append" the full resulting list.
- MCP server: order and refund previews say exactly which items will and will not move stock.
- MCP server: previews come back as a normal result rather than an error, so AI assistants and MCP clients no longer mistake them for a failure.
- MCP server: errors carry a code the AI assistant can read.
- MCP server: reports and order lists use the shop's time zone for dates like "today".
- MCP server fix: variations created by an AI assistant on attributes with non-Latin names were saved as "any value".
- MCP server fix: a taxonomy filter without an operator, or with "OR", matched the whole catalogue instead of the chosen terms.
- MCP server fix: search by product title and sorting of results.
- MCP server fix: the upload page respects the server's upload size limit and numbers the files correctly.
- MCP server fix: with the FOX currency switcher, orders created by an AI assistant could get a doubled subtotal, and reports could convert amounts twice.
- MCP server fix: refunds with restock now actually return goods to stock, and orders created with stock reduction off no longer reduce it.
- MCP server fix: sales, stock and refund reports now count variations under their own ids.
- Fix: CSV exports are no longer left accessible in the plugin folder, and old export files are removed after 8 hours.
- Fix: product titles containing HTML are shown as text in the editor.
- Security: audited all AJAX handlers and added the missing nonce, capability and ownership checks. Reported by Ali Mousavi via WPScan: a taxonomy term update handler with no nonce or capability check, a meta field config handler with no nonce, and several read-by-id handlers that returned another products meta and protected download links to any logged in user. The audit covered every handler in the plugin, not only the reported ones, and the checks now run through a single guard in WOOBE_HELPER
- NEW: MCP server - connect Claude, ChatGPT or any MCP capable agent to your shop and work with it in plain language: filter and bulk edit products, get sales, stock and refund reports, export CSV. Every change shows a preview first and is revertible from History: /document/mcp-server
- Fix: several issues found while building it - the plugin did not initialise on REST requests, currency switcher filters could distort prices read outside the editor screen, sale end dates depended on which columns a user had visible, single field edits outside the editor skipped value preparation, and unquoted attributes in draw_select_e() broke the History author filter
- Fix: saving the settings form could wipe shop wide options that were not on screen for the current user
- Fix: memory storage https://pluginus.net/support/topic/plugin-purges-object-cache/
- Fix: "Invalid Date" error in calendar picker when sale date field is empty
- Improvement: Codebase aligned with WordPress Coding Standards (WPCS) and PluginCheck recommendations.
- Security fix, thanks to Bonds and patchstack.com
- Fix: Sale price range filter could return incorrect results in certain edge cases. Type handling improved for reliable numeric comparison.
- Fix: Regular price range filter had the same issue and has been corrected.
- Fix: Improved handling of empty values in price filters.
- security fix, thanks to daroo and patchstack.com
- set of small fixes
- security fix, thanks to daroo and patchstack.com
- 2 security fixes, thanks to Dmitrii Ignatyev and wordfence.com
- Set of small fixes
- Fixes for the new CSS design, thanks to user feedback
- Fix about gallery-button update after img is removed
- New feature: you can now create a woobe.css file in your current WordPress theme folder to fully customize the BEAR admin panel appearance
- security fix, thanks to Satrya wira yudha and patchstack.com
- security fix, thanks to Dhabaleshwar Das from patchstack.com
- security fix, thanks to Rafie Muhammad from patchstack.com
- data tables js fix
- security fix, thanks to Mika from patchstack.com
- some minor fixes
- fixed accidental hard code, hooks added: woobe_hide_filters_by_attribute and woobe_hide_bulk_by_attribute
- security fix, thanks to Nguyen Xuan Chien from patchstack.com
- quick fix for wordpress 6.0 cache
- quick fix for search panel in the products editor
- fixes for operations by author
- new hook woobe_product_statuses - allows to add more products statuses
- bunch of small fixes
- ability to set fields empty
- hook woobe_storage_type to fix filtering if troubles with session: read here
- jQuery fixes for WordPress 5.6 compatibility
- small fixes
- fix for delete button enabling
- Hot fix for WordPress 5.3 update
- Some minor fixes
- Added Filter by authors
- Added Filter by catalog visibility
- Added Bulk edit by author
- Added Bulk deleting
- some bug fixes and improvements about serialized (json) meta fields bulk edit
- ALT key removed from Products editor navigation
- small fixes
- reading of data from data base became for 300% quicker thanks to caching products objects
- added ability of bulk editing serialized data in meta fields
- Release