This is a security update. This fix was applied to versions 1.6.0 and 1.6.1 and is also in the new version 22.214.171.124.
Please note: If you do not have a magic tag in your success message, which is not a default setting, this issue does not affect you. We still recommend keeping your plugins up to date.
Bottom line: I missed something. That’s my mistake and I apologize. – Josh
Caldera Forms 126.96.36.199 adds the same protection in one more location and prevents the behaviour that was shown to me today.
What You Should Do
Again, if you do not have a magic tag in your success message, which is not a default setting, this issue does not affect you. Still, you should keep your plugins up to date.
- Update to Caldera Forms 188.8.131.52 through WordPress now. This update was done to trigger update notices.
- You can also use WP Rollback to re-install 1.6.0 or 1.6.1, which have the fix.