Leaky Paywall Updates: September 2026

Fifteen releases rolled out in September across the core plugin and nine add-ons. The focus: keeping subscriber data private and making sure what your site records matches what Stripe actually charged.

Running Double Opt In or Group Accounts? Update those first. Both releases close a vulnerability that could let an attacker get into another subscriber’s account.

The highlights

Account activation vulnerability closed (Double Opt In 1.5.0, Group Accounts 1.7.5). A flaw in the activation flow for both add-ons could give an attacker access to another subscriber’s account. It is fixed in both. Update now if you use either one.

Subscriber data stays private (5.1.8). Detailed debug logging is now off by default, and the log lives in a protected folder with a new unguessable name each time you turn it on. Subscriber exports are no longer saved to a public location: only a logged-in admin can download them, and they are removed once downloaded. Old log and export files from earlier versions are deleted on update.

Imports clean up after themselves (5.1.8). The Import tool now deletes the uploaded CSV from your Media Library when the import finishes, so a file full of subscriber data is not left sitting on your site. This is on by default.

Trial and level change billing fixed (5.2.0, Trials 1.9.7, Recurring Payments 1.6.5). Upgrading during a free trial now starts billing right away instead of giving free access until the old trial end. Level changes now record the real Stripe invoice, not the level’s list price or a payment that never happened. And an existing subscriber switching onto a level with a delayed trial is no longer charged the trial’s initial payment on top of what they already paid.

Recurring coupons work with Stripe (Coupons 2.4.8). Coupons set to discount every payment, not just the first, were being rejected by Stripe at checkout. They now go through.

SimpleCirc logins no longer cut expiration dates short (SimpleCirc 2.1.1). For print and digital subscriptions, SimpleCirc’s date is the last issue date, which can be months before renewal. The login sync was replacing the correct Leaky Paywall expiration with it. That is fixed.

Every email now matches your brand. We covered the new Payment Receipt email and branded email template in a previous update. This month, the rest of the add-ons caught up: cancellation, gift, corporate welcome, group invitation, and double opt in verification emails all use your template now. See the setup guide.

See who converted on each article (5.2.0). The Top Content cards on your dashboard now link straight to the subscribers each article converted, free and paid, with a CSV download. Free readers also get an upgrade prompt on their account page. Read the full 5.2.0 rundown.

Looking to grow your publication?

Sign up for expert advice straight to your inbox.
This field is for validation purposes and should be left unchanged.

Before you update

Two fixes this month depend on the latest core version:

  • Trials 1.9.7 and Recurring Payments 1.6.5 trial fixes require Leaky Paywall 5.2.0.
  • Recurring Payments 1.6.4 or later is needed for 5.1.9’s move to the Stripe Prices API.

Update core to 5.2.0 first before updating your add-ons.

Plugin updates by name

Leaky Paywall (core), 5.1.8

  • Detailed debug logging is off by default and can be turned on under Leaky Paywall > Tools > Debug Log. Errors are always recorded. Logs are capped at 5 MB or 30 days
  • Define LEAKY_PAYWALL_LOG_DIR in wp-config.php to store the log outside your website folder
  • Subscriber exports are delivered as an admin-only download and removed once downloaded
  • Import tool can delete the uploaded CSV from your Media Library when the import finishes
  • Account deletion emails now list the Stripe subscriptions that were cancelled, or confirm there were none
  • Admin notices warn when an access setup would silently lock subscribers out
  • Subscriber search now matches account details and subscriber data together when a filter is applied
  • An abandoned Stripe registration no longer removes access from a subscriber who signed up twice on the same Stripe customer

Leaky Paywall (core), 5.1.9

  • New Payment Receipt email for every payment, including renewals, with resend from any transaction
  • New branded email template with logo, accent color, footer text, and a Send Test Email button
  • Stripe subscriptions now use Stripe’s current Prices API
  • On multisite, one gateway webhook endpoint can finalize a registration started on any site in the network
  • Free subscribers added through the REST API on a Forever level now never expire, as intended (this also affected the default Free Registration level)
  • Fixed a “Could not create subscription” error at checkout on sites running an older Recurring Payments add-on
  • Fixed errors tied to old Stripe plan IDs and missing subscriber levels

Leaky Paywall (core), 5.2.0

  • Article-level conversion tracking with subscriber lists and CSV download (Pro)
  • Upgrade prompt for free subscribers on their account page, with editable heading, description, and button text
  • Switch to turn off the branded email template if you send your own fully designed HTML
  • New Level Change transaction type with its own filter
  • Colored status badges for pending, trialing, past due, pending cancellation, and inactive
  • List Builder overlay no longer flashes when a performance plugin defers the stylesheet
  • Plan changes and renewals covered entirely by Stripe account credit are no longer treated as completed payments
  • Fixed a double paywall notice and double meter count on sites where another plugin starts the REST API early

LP – Recurring Payments, 1.6.4

  • Stripe plan handling updated for Leaky Paywall 5.1.9 and the Stripe Prices API

LP – Recurring Payments, 1.6.5

  • Level changes from the account page record only the invoice the change generated, and a change that bills nothing is recorded as zero
  • Changing levels during a free trial now starts billing (requires Leaky Paywall 5.2.0)
  • Level changes are labelled as level changes on the transactions screen
  • Cancellation emails use your Leaky Paywall email template

LP – Double Opt In, 1.5.0

  • Security fix for the account activation flow
  • Pending to active status changes now show in status history and connected integrations
  • Clearer activation page wording, and signed-in visitors are sent to their account

LP – Double Opt In, 1.5.1

  • Signups on a double opt in level are recorded as pending from the moment the account is created
  • Verification code email uses your Leaky Paywall email template

LP – Group Accounts, 1.7.5

  • Security fix for the group member activation flow
  • Group invitation and removal emails use your Leaky Paywall email template
  • Clearer activation page, tidier password fields, and signed-in visitors are sent to the group dashboard

LP – Coupons, 2.4.8

  • Coupons that discount every payment now work with Stripe

LP – SimpleCirc, 2.1.1

  • SimpleCirc logins no longer shorten a subscriber’s Leaky Paywall expiration
  • On multisite, the SimpleCirc account ID is stored once per reader, so linked subscribers are found on every site

LP – Trials, 1.9.7

  • Subscribers switching onto a delayed-trial level are no longer charged the trial’s initial payment
  • Trial end date is cleared when a trial ends, so a later cancellation no longer rolls expiration back (requires Leaky Paywall 5.2.0)
  • Delayed trials now apply to new subscribers only

LP – Trials, 1.9.8

  • Paid subscribers with a moved Stripe billing date are no longer relabeled as Trial
  • Trial status changes appear in status history and are sent to Insights

LP – Gift Subscriptions, 3.3.1

  • Gift details are no longer autoloaded on every page request, and existing records are switched over automatically
  • Gift purchaser and recipient emails use your Leaky Paywall email template

LP – Corporate Subscriptions, 1.9.3

  • Corporate welcome emails use your Leaky Paywall email template

LP – Timewall (Auto Archiver), 3.5.5

  • Archived content now shows the archive message instead of the List Builder signup
  • Archived content is reported as its own paywall type in Insights

Updated resources

Payment Receipt Email and Branding. How to turn on receipts, add your logo and colors, and send test emails. Read the guide.

Premium Archive Access add-on. Updated to explain that archived posts now show your archive message instead of the List Builder signup. Read the guide.

Questions about how any of this applies to your setup? Reply to this email.

Thanks for being a Leaky Paywall publisher.

Learn how Leaky Paywall can help grow your subscription revenue