CubeCart 6.7.4 was released on 3 June 2026. After the security-only 6.7.3 that preceded it, this is a feature release again, and its headline addition is a statutory cancellation workflow that UK and EU merchants have been handling manually by email until now.
Customers can now formally request to cancel an order, in the system, with an audit trail. The Right of Withdrawal feature gives shoppers a way to submit a cancellation or return request against an order directly from their order list or receipt. You get a management screen under Customers, Withdrawal Requests, with states for new, accepted, rejected and refunded, plus acknowledgement and decision emails that go out automatically.
Why this matters: under the UK Consumer Contracts Regulations 2013 and the EU Consumer Rights Directive, distance selling customers generally have a 14 day cooling off period in which they can withdraw from the contract, and you are required to acknowledge such requests. Most CubeCart merchants have been running this through their normal support inbox. Doing it in the store means the request is attached to the order, the acknowledgement is automatic and timestamped, and you can show what happened if it is ever disputed.
To be clear about what this is: it is a workflow tool, not a compliance guarantee. It does not decide which of your products are exempt, it does not set your refund timescales, and it does not write your policy for you. It gives you a consistent process and a record. If you are unsure where you stand on cooling off rights for what you sell, take proper advice.
Scheduled tasks can now run properly from the command line. There is a dedicated CLI cron runner, which is the correct way to run scheduled work on a real store. More on this below, and it is the single change in this release most likely to fix a nagging reliability problem you already have.
Your orders table will get smaller. Order baskets are now stored gzip compressed. On a store with a long order history this can be a substantial saving, and the upgrade backfills historic orders for you in the background.
New database table CubeCart_withdrawal_requests. Admin screens at admin/sources/customers.withdrawals.inc.php with index and detail templates. Storefront templates content.withdraw.php and content.withdraw.done.php in the Foundation skin. Three new email templates are imported across every shipped language during upgrade.

The new EU Withdrawal Function setting on the Features tab.
Click for full sized image
If you run a custom skin rather than Foundation, the two storefront templates will not exist in your skin and the customer facing side of this will not appear until you add them. That applies to any of our skins too, and it is the kind of thing worth checking on a staging copy rather than discovering live. The withdrawal email macros were tidied further in 6.7.5.
New entry point at cli/cron.php, with a cli/.htaccess that denies direct web access to the directory. The cron dispatcher logic was hardened at the same time, and session and cron timing was tightened to a one hour window.
This matters more than it sounds. Before this, scheduled tasks were realistically driven by web requests, which means they run when somebody visits your site, they compete with real customer traffic, and on a quiet store they may not run at all when you need them to. A real cron entry calling cli/cron.php runs on a schedule you control, under the CLI PHP binary, without a web request. If you have abandoned cart emails or newsletters that seem to fire erratically, this is the fix.
You will need to add the cron job yourself, at server or control panel level. If you host with us, ask and we will set it up.
Four issues covering a phased rework of api.php: cleaner routing, better request handling, then a final consolidation pass. The nine resources from 6.6.0 are unchanged in scope; this is internal restructuring rather than new surface area. Combined with the file upload vulnerability fixed in 6.7.0, the API is in a considerably better state here than it was at its beta debut.
CubeCart_order_summary.basket is now stored gzip compressed and the column was widened to MEDIUMBLOB. The upgrade script setup/scripts/upgrade/6.7.4.php backfills historic non-Pending orders in batches rather than in one transaction, which is the right call on a large table. Pending orders are deliberately left uncompressed and compress on their next status change, so an in-flight order is not touched mid-checkout.
On a store with tens of thousands of orders this is a real disk and backup saving. Give the background backfill time to finish before drawing conclusions about table size.
Four improvements, one of which is genuinely useful for anyone doing management accounts: statistics can now be reported by accounting reference date as well as order date. Best selling products can be viewed by month, a chart sizing bug was fixed, and bot and crawler visits are now separated from genuine traffic in visitor statistics. That last one will make your visitor numbers look worse and your conversion rate look better, both of which are more honest.
Plugin and extension auto-updates are surfaced on the dashboard and extensions page. A sticky save bar was added to long admin forms. The redundant admin_skin config setting was removed and the bundled default skin is always used now. Page break issues on the customers, orders, products and dashboard listings were fixed.
There is also an in-admin support and live chat widget (classes/supportwidget.class.php) for active CubeCart subscribers.
On the PHP 8 hardening side: an array_merge() warning fixed, an output buffer guard added, a Smarty MuteExpectedErrors handler to suppress expected template filesystem notices, graceful handling when a visitor has cookies blocked, and the configured adminFolder and adminFile now preserved through the request lifecycle.
Abandoned cart recovery got stability improvements and additional test coverage, though the significant fix in that area (reminders going to customers who had already paid) did not arrive until 6.7.6.
Not to 6.7.4 as an endpoint. 6.7.5 and 6.7.6 both fixed responsibly disclosed vulnerabilities that 6.7.4 is exposed to, including two SQL injections and a Smarty policy bypass. Go to the current release.
What 6.7.4 is worth knowing about is the withdrawal workflow, which you may not have realised your store now has, and the CLI cron runner, which you probably should be using and may not be.
If you host your CubeCart store with us and want the cron entry set up properly, or want the withdrawal templates checked against a custom skin before you go live with them, get in touch.