Fixed a CAPTCHA bypass vulnerability in the Contact Form, Opt-in Form and Form Builder addons when placed inside a module, ensuring the CAPTCHA plugin's verification result is always enforced. (Pro only) [CVE-2026-79701]
Fixed a cross-site scripting vulnerability in the Dynamic Content Filter addon, where the slider minimum and maximum values taken from the query string were escaped in the data-value attribute but not in the element's text content. Both occurrences are now escaped. (Pro only) [CVE-2026-102426]