Bagisto latest version 2.4.13 closes a run of security gaps across orders, refunds, payments and the admin. It carries no new features of its own.
- First, Bagisto v2.4.13 checks every invoice, shipment and refund against the order you are actually working on.
- A refund can no longer exceed the shipping it originally charged you for the order.
- A cart quantity with a decimal point no longer saves as a rounded figure while Bagisto bills you the exact one.
- Stripe now applies your cart rule discount on its own payment page.
- PayU no longer drops an order when a shopper never returns to confirm it.
- Finally, Bagisto v2.4.13 fixes a free product’s price and a customer’s address form.
- It also fixes the account, copyright and GDPR pages your shoppers see.

Overall, these changes in Bagisto v2.4.13 close the security gaps this release found. They also keep orders, accounts and the storefront accurate.
You can check release on GitHub.
Bug Fixes in Bagisto Version 2.4.13
Order, Invoice and Refund Fixes
- Fixed invoices and shipments accepting a product that belonged to a different order.
- Bagisto now checks every item you name against the order you are acting on.
- Fixed a refund accepting more shipping than the order’s invoice actually listed.
- A crafted request could have used this to refund far more than the order’s total.
- The refund amount now stops at the shipping Bagisto invoiced you for.
- It subtracts anything you already refunded, exactly as the form already showed you.
Cart and Pricing Fixes
- Fixed a cart quantity typed with a decimal point saving as a rounded whole number.
- Bagisto still billed the customer the figure they actually entered.
- A cart quantity now has to be a whole number. Leaving it at zero still empties the line, as before.
- Fixed cart rules starting and ending up to an hour early or late.
- Bagisto had been comparing their start and end times against the current month, not the current minute.
Payment Fixes
- #11516 Fixed a PayU payment leaving no order behind when the shopper never returned to your store.
- An in-app browser made this easy to hit.
- PayU’s own server-to-server notification now places that order, once, however the shopper’s browser behaves.
- Fixed Stripe charging a shopper the full price even after a cart rule had discounted their order.
- The discount now shows on Stripe’s own payment page.
- A fractional unit price no longer loses a penny to rounding.
Customer Account Fixes
- Fixed the customer addresses page answering with a server error. The url now opens the addresses on the customer’s own account screen.
- #11511 Fixed a phone number written the way people normally write one, with spaces, dashes or brackets.
- Checkout and the address forms no longer reject it.
- #11510 Fixed the customer address form discarding the postcode and the second and later street lines.
- This happened whenever the form came back with a validation error.
- #11504 Fixed the account overview, which carried the title and breadcrumb Orders instead of its own.
- The account menu’s greeting and profile picture description also stayed in English in every locale.
Catalogue and Appearance Fixes
- Fixed a product page failing with an error when a product and its customer group price both equalled zero. A free product now simply shows no discount.
- Fixed the seeded Top Collections section keeping its demo pictures in another section’s folder.
- Deleting or editing one of them used to remove the pictures of the other.
- #11501 Fixed a fatal error when publishing or previewing a Product Carousel section.
- The Appearance editor had named the channel one way, where the rest of Bagisto names it another.
Admin, Storefront and Platform Fixes
- Fixed the admin notification feed handing every order’s details to any signed-in admin, whatever their role allowed.
- Those details included the customer’s name, email, totals and status.
- The feed, the notification screen and the bell now all follow the same permission that already guards orders.
- #11513 Fixed a generated sitemap that only its own owner could read.
- This left the sitemap url answering not found until someone fixed the permissions by hand.
- #11509 Fixed the storefront copyright notice, which every channel used to share.
- It now carries its own notice per channel as well as per locale.
- A migration carries your existing notice over automatically.
- #11503 Fixed the GDPR pages showing the default theme’s not-found page instead of your channel’s own.
- This happened on every GDPR page while you switch GDPR off, unlike every other storefront page.
This release also includes further automated security fixes.
In short, the fixes in Bagisto v2.4.13 close this release’s security gaps, and keep orders, accounts and the storefront accurate.
Conclusion
- Overall, Bagisto v2.4.13 is a security and reliability release, and it carries no new features of its own.
- It checks invoices, shipments and refunds against the right order.
- It also keeps a refund inside the shipping it actually charged you.
- Stripe now applies your cart rule discount on its own page.
- PayU no longer drops an order when a shopper never returns to confirm it.
- Bagisto v2.4.13 also fixes a free product’s price and a customer’s address form.
- It also fixes the account, copyright and GDPR pages your shoppers see.
- Above all, this release keeps your store secure and accurate while you run it on the open-source platform.
Thanks for reading this Bagisto v2.4.13 release note. If you have any questions, please feel free to comment below.
Also you can hire laravel developers for your custom laravel projects. Kindly explore our extensions.
. . .
Be the first to comment.