Fix - Calling acf_get_reference() with an invalid field name no longer causes a fatal error
Enhancement - Error messages that occur when field validation fails due an insufficient security nonce now have additional context Fix - Duplicated ACF blocks no longer lose their field values after the initial save when block preloading is enabled Fix - ACF Blocks containing complex field types now behave correctly when React StrictMode is enabled
Enhancement - Field Group keys are now copyable on click Fix - Repeater tables with fields hidden by conditional logic now render correctly Fix - ACF Blocks now behave correctly in React StrictMode Fix - Edit mode is no longer available to ACF Blocks with an WordPress Block API version of 3 as field editing is not supported in the iframe
Security - Editing an ACF Field in the Field Group editor can no longer execute a stored XSS vulnerability. Thanks to Duc Luong Tran (janlele91) from Viettel Cyber Security for the responsible disclosure Security - Post Type and Taxonomy metabox callbacks no longer have access to any superglobal values, hardening the original fix from 6.3.8 further Fix - ACF fields now correctly validate when used in the block editor and attached to the sidebar
Security - ACF defined Post Type and Taxonomy metabox callbacks no longer have access to $_POST data. (Thanks to the Automattic Security Team for the disclosure)
Security - Newly added fields now have to be explicitly set to allow access in the content editor (when using the ACF shortcode or Block Bindings) to increase the security around field permissions. See the release notes for more details Security Fix - Field labels are now correctly escaped when rendered in the Field Group editor, to prevent a potential XSS issue. Thanks to Ryo Sotoyama of Mitsui Bussan Secure Directions, Inc. for the responsible disclosure Fix - Validation and Block AJAX requests nonces will no longer be overridden by third party plugins Fix - Detection of third party select2 libraries will now default to v4 rather than v3 Fix - Block previews will now display an error if the render template PHP file is not found
Fix - The ACF Shortcode now correctly outputs a comma separated list of values for arrays Fix - ACF Blocks rendered in auto mode now correctly re-render their previews after editing fields Fix - ACF Block validation no longer raises required validation messages if HTML will automatically select the first value when rendered Fix - ACF Block validation no longer raises required validation messages if a default value will be rendered as the field value Fix - ACF Block validation no longer raises required validation messages for fields hidden by conditional logic when adding a new block
Security Fix - The ACF shortcode now prevents access to fields from different private posts by default. View the release notes for more information Fix - Users without the edit_posts capability but with custom capabilities for a editing a custom post type, can now correctly load field groups loaded via conditional location rules Fix - Block validation no longer validates a field’s sub fields on page load, only on edit. This resolves inconsistent validation errors on page load or when first adding a block Fix - Deactivating an ACF PRO license will now remove the license key even if the server call fails Fix - Field types returning objects no longer cause PHP warnings and errors when output via the_field, the_sub_field or the ACF shortcode, or when retrieved by a get_ function with the escape html parameter set Fix - Server side errors during block rendering now gracefully displays an error to the editor
FIX - ACF Blocks no longer trigger a JavaScript error when fetched via AJAX
Subscribe to get access to unlimited premium items from our community of global authors and developers.
Last update:
19-04-2025 06:09 AM
Published:
07-06-2024 11:53 PM
Version:
Category:
Tags: