AccessAlly 4.9 & 4.9.1
Released July 7, 2026 and August 12, 2026
These two releases are largely about security. Between them they harden most of the plugin against tampering, remove third-party tour scripts from your admin, and fix a checkout problem affecting fully discounted one-time products. Nothing here changes how AccessAlly works day to day, so these are safe updates to take.
Security
- AccessAlly now escapes everything it outputs, on your admin screens and on your site’s pages, including the text of any internal error it reports. This was a systematic pass over the whole plugin rather than a fix to one spot, and it does not change how anything looks or behaves.
- Every admin action AccessAlly performs now checks a one-time token before it runs. This means a link or a form on another website cannot quietly trick one of your logged-in administrators into making changes on your site.
- We rewrote the parts of the plugin updater that talk to our servers. It now uses a secure connection throughout, validates what comes back rather than trusting it, and verifies the request before performing an update.
- We added a security disclosure note to the plugin, so that security researchers know how to report anything they find directly to us.
Improvements
- We removed the Chameleon product tour tool from AccessAlly. Its scripts no longer load anywhere in your WordPress admin, which means one less third party receiving information about your site, and a slightly lighter admin as well.
- The reCAPTCHA settings for both order forms and opt-in forms now tell you up front that only reCAPTCHA v2 Invisible is supported. Pasting v3 keys into those fields does not work, and previously nothing on the screen warned you before your forms stopped accepting submissions.
- On the screen for converting to AccessAlly Managed contacts, any step with nothing to move is now highlighted in red. Previously a step showing zero looked much like a step with work to do, which made it easy to assume something had been missed.
- When Ontraport rejects a request, AccessAlly now records the specific reason Ontraport gave in the developer log instead of a generic failure. This makes integration problems considerably faster to diagnose.
- If installing or activating an add-on fails, you now get a clear error explaining why, rather than a button that appears to do nothing.
- The migration option has been removed from the settings area. To bring existing members into line with your CRM, use Permissions and then Sync Users.
- We updated the address AccessAlly uses to check your license, so licensing requests now go to accessally.com directly. If your host or firewall restricts outgoing connections, this is worth passing along to them.
Bug fixes
- We fixed credit card fields appearing on order forms for one-time products when a coupon brought the first payment down to zero. AccessAlly was treating the order as though a future payment was still coming, so buyers were asked for card details that were never going to be charged, and a card setup request was sent to Stripe unnecessarily. Coupons that discount an actual subscription are unaffected and behave as before.
- We fixed the page jumping around when you open or close a toggle. The toggle you clicked is now scrolled into view, so the content you were reading stays where you expect it.
- We fixed links generated by the tag shortcode breaking when they contained special characters. Those links are now encoded properly.
Known issue
- On the Sales page, some sites see an “Invalid Subscription ID.” message appear as soon as the page loads, which has to be dismissed each time. This is cosmetic. It does not indicate a problem with any subscription, it does not affect your orders, your subscriptions or your data, and nothing is blocked by it. The cause was introduced in 4.9.1, we have already fixed it, and the fix is included in the next release.


