Advanced Custom Fields v6.3.2
Release Date 24th June 2024
- Security Fix - ACF now generates different nonces for each AJAX-enabled field, preventing subscribers or front-end form users from querying other field results
- Security Fix - ACF now correctly verifies permissions for certain editor only actions, preventing subscribers performing those actions
- Security Fix - Deprecated a legacy private internal field type (output) to prevent it being able to output unsafe HTML
- Security Fix - Improved handling of some SQL filters and other internal functions to ensure output is always correctly escaped
- Security Fix - ACF now includes blank index.php files in all folders to prevent directory listing of ACF plugin folders for incorrectly configured web servers