WooCommerce 11.2: What You Need to Know

WooCommerce 11.2 was officially released yesterday, October 7, 2026. This release brings handy new features for store owners, as well as essential security updates for WordPress admins.

As per usual, Seravo takes care of site performance and reliability, but here is a quick overview of what’s changing and what you should know about the latest release!

What’s New in WooCommerce 11.2?

You can also check the full release notes on GitHub. Below is a list of the most important changes to know about.

Smarter Product CSV Importer

Match rows by GTIN, UPC, EAN, or ISBN when updating existing products. This makes inventory syncs smoother, even if you’re not using standard IDs or SKUs.

Checkout Block Date Fields

Developers and extensions can now collect customer dates (such as birth dates or preferred delivery days) directly through the Checkout block API.

Configurable Withdrawal Emails

The right for order withdrawal for EU customers was implemented previously in WooCommerce 11.1. Now, store owners gain direct control over the incoming order withdrawal request notifications right in the dashboard, WooCommerce > Settings > Emails.

More Block Styling

Extra customization options have been added across core WooCommerce blocks for theme developers and site builders using WordPress Global Styles. Read more about Global Styles on learn.wordpress.org.

Security Updates

Emails

This release contains key security updates across several areas, most visibly in emails sent by WooCommerce: CC and BCC fields have been excluded from the options, so that there would be less exposure for user password reset and account confirmation emails, for exmaple.

For developers who need a copy for an integration can still add one through the woocommerce_email_cc_recipient_{email_id} and woocommerce_email_bcc_recipient_{email_id} filters.

Downloadable Products

In WooCommerce 11.2, security for downloadable products (such as digital goods) is improved by link authorization, which validates order and email credentials. Any malformed requests are blocked.

Here’s what to know: standard download links will not be affected by this update, and most store owners won’t notice any change. However, any links containing legacy or custom configurations may break.

If your store’s links stop working, you can resolve it by reissuing the download link (by accessing WooCommerce dashboard/order information), regenerating permissions (although this will reset download counts and logs), or fixing the database permissions.

Other Security Updates

WooCommerce 11.2 also hardens security in other ways as well:

  • Shop Managers can no longer edit user accounts that hold extra or higher privileges.
  • In addition, Blueprint (portable Woo configuration files) imports on multisites (WordPress networks) now require full Super Admin user rights.
  • Lastly, opt-in usage tracking automatically filters out sensitive store data before sending it.

See the original WooCommerce release notes on their developer blog!

Seravo – Recommended by WooCommerce

Did you know that Seravo’s premium hosting is officially recommended by WooCommerce? Get to know our hosting and try it for free today!