
3 Min Read
Paymattic 4.6.26: Server-Side Dashboard Pagination, Security Hardening, and More!
Table of Content
Download Paymattic – it’s Free!

Subscribe To Get
WordPress Guides, Tips, and Tutorials
We will never spam you. We will only send you product updates and tips.
Paymattic 4.6.26 is here!
This latest release improves User Dashboard performance and strengthens security across Stripe, Razorpay, Mollie, and the core submission pipeline.
This release includes:
- Server-side pagination for User Dashboard submissions
- Stronger payment and webhook verification
- Better isolation of user submission data
- Stripe payment-flow correctness fixes
- Stability and input-validation improvements
What’s new
Faster user dashboard submission history
Sites with large submission histories previously had to load every entry before the dashboard could render. For users with hundreds of submissions, this could lead to slow page loads, heavy database queries, and long waits.
Paymattic 4.6.26 now paginates User Dashboard submissions on the server. The database returns only the page a user is viewing, keeping load times consistent as submission histories grow.
This is especially useful for:
- Membership sites with years of recurring payment history
- Event organizers managing repeat registrations
- Nonprofits supporting high-volume donor accounts
- Finance and operations teams reviewing submissions for reconciliation
No configuration is required. Server-side pagination is applied automatically after updating.
Fixes
Security and data isolation
- Stripe SCA confirmation: PaymentIntents are now verified against the originating submission before the payment status is updated, preventing cross-submission confirmation.
- Razorpay redirects and callbacks: Returned payment IDs are validated against the expected submission before processing.
- Mollie IPN events: Payment metadata is re-fetched from Mollie, and the
submission_idis verified before an event is processed. - Draft form previews: Preview access is restricted to authorized users, preventing unpublished forms from being discovered by guessing post IDs.
- Integration notifications: Notification endpoints now require an authenticated session.
- Stripe webhooks: Events are re-fetched from Stripe’s API instead of being trusted solely from the raw payload.
- User Dashboard submissions: Queries are now scoped strictly to the authenticated user’s own account.
Stripe payment correctness
- Hosted Checkout cancellations: The cancel handler checks the current payment status before making changes, so already-paid submissions remain unchanged.
- Subscription renewal refunds: Refund processing now targets only the renewal transaction instead of incorrectly marking the original payment as refunded.
- Stripe Connect customer lookups: Customer API calls now use the correct account-specific key in connected-account setups.
- Embedded subscription payments: The displayed amount now reflects the correct subscription plan amount.
Stability and validation
- Elementor popups: Step and conditional listeners are cleaned up when a popup closes, preventing duplicate events when it reopens.
- Item quantities: Values that overflow
absintare rejected after sanitization. - Pricing indexes: Array bounds are checked before a pricing index is accessed.
- Subscription plan indexes: Plan indexes are validated before they are dereferenced.
Update Paymattic
Paymattic 4.6.26 is available now in WordPress. Go to Dashboard → Plugins → Updates and select Update for Paymattic. You can also download the update from your paymattic.com account.
If you notice anything unexpected after updating, contact the Paymattic support team.
Join the thousands already enjoying Paymattic Pro!
Md Shahjahan
Hello, this is Jewel, CEO & Head of Ideas at WPManageNinja. I am obsessed with WordPress since 2009. My aim is to be a user-centric developer first, and a serial entrepreneur second. You will find me discussing various tech issues and trying to come up with scalable solutions on different forums when I am not busy coding.








Leave a Reply