This release fixes a critical vulnerability and several related
access-control issues. Updating is strongly recommended for all users.
Security
- Critical – Shipping labels download protection
- Callback webhook now verified.
- SQL injection hardened.
- Open redirect fixed.
- CSRF protection added
No database changes are required; simply update the plugin.
Credits
Thanks to Tijmen Kivit for responsibly reporting the label download
vulnerability.