Decryption key:
Enfold - Responsive Multi-Purpose Theme v8.1
Patchstack team XSS vulnerability report: Cross-Site Scripting in backend
Patchstack team report: manipulated demo and theme settings import requests
Patchstack team report: API keys and secrets exposed through theme settings export
tweak: Element settings windows open much faster - icon sets and colour pickers inside a closed options section are now built only when you open that section, instead of every time the window opens
fixed: pages using Portfolio, Blog, Masonry or other elements that list entries could fail to load after content was brought over from another installation, when the categories it refers to do not exist on this site
fixed: the element settings window could fail to open for an element whose shortcode is not available on this site, for example content imported from an installation that had a plugin this one does not
fixed: PHP warnings on pages using tab elements with a custom top or bottom margin or padding
fixed: Turnstile script loading and improved error handling
fixed: fetchpriority="high" was incorrectly added to below-the-fold images
fixed: PHP 8.2 deprecation notices shown in the backend after a theme update
fixed: WooCommerce orders, refunds, and subscriptions could be duplicated via the Duplicate row action
fixed: minor UI issues in the classic top toolbar
fixed: hardened demo and theme settings import against manipulated import requests
fixed: demo content is no longer partially stripped when a site administrator imports a demo on multisite
fixed: API keys, secret keys and the Google Analytics tracking code are no longer included when exporting theme settings
tweak: importing theme settings and Layout Builder template files is now available to site administrators on multisite (previously super admins only)
tweak: your Envato personal token is no longer stored as part of a database option name