Advanced Custom Fields Pro v6.3.10 Release Date 29th October 2024
Security - Setting a metabox callback for custom post types and taxonomies now requires being an admin, or super admin for multisite installs
Security - Field specific ACF nonces are now prefixed, resolving an issue where third party nonces could be treated as valid for AJAX calls
Enhancement - A new “Close and Add Field” option is now available when editing a field group, inserting a new field inline after the field being edited
Enhancement - ACF and ACF PRO now share the same plugin updater for improved reliability and performance
Fix - Exporting post types and taxonomies containing metabox callbacks now correctly exports the user defined callback
Advanced Custom Fields Pro Release Note v6.3.9 = Release Date 15th October 2024
Security - Editing an ACF Field in the Field Group editor can no longer execute a stored XSS vulnerability. Thanks to Duc Luong Tran (janlele91) from Viettel Cyber Security for the responsible disclosure
Security - Post Type and Taxonomy metabox callbacks no longer have access to any superglobal values, hardening the original fix from 6.3.8 further
Fix - ACF fields now correctly validate when used in the block editor and attached to the sidebar
Security - Newly added fields now have to be explicitly set to allow access in the content editor (when using the ACF shortcode or Block Bindings) to increase the security around field permissions. See the release notes for more details
Security Fix - Field labels are now correctly escaped when rendered in the Field Group editor, to prevent a potential XSS issue. Thanks to Ryo Sotoyama of Mitsui Bussan Secure Directions, Inc. for the responsible disclosure
Fix - Validation and Block AJAX requests nonces will no longer be overridden by third party plugins
Fix - Detection of third party select2 libraries will now default to v4 rather than v3
* Fix - Block previews will now display an error if the render template PHP file is not found
Security Fix - The ACF shortcode now prevents access to fields from different private posts by default.
Fix - Users without the edit_posts capability but with custom capabilities for a editing a custom post type, can now correctly load field groups loaded via conditional location rules
Fix - Block validation no longer validates a field’s sub fields on page load, only on edit. This resolves inconsistent validation errors on page load or when first adding a block
Fix - Deactivating an ACF PRO license will now remove the license key even if the server call fails
Fix - Field types returning objects no longer cause PHP warnings and errors when output via the_field, the_sub_field or the ACF shortcode, or when retrieved by a get_ function with the escape html parameter set
Fix - Server side errors during block rendering now gracefully displays an error to the editor.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.