- Security fix: required an administrator capability and a nonce on the license AJAX actions, so a logged-in Subscriber can no longer clear or overwrite the stored license and subscription data — thanks to NAWardRox (CVE-2025-32220)
- Security fix: required a nonce on privileged salon AJAX (calendar locks, booking search, customer lookup, notification resend, extension install, booking totals) and required login, nonce and booking ownership on the My Account reschedule date-check


