Advanced Custom Fields PRO

Advanced Custom Fields PRO 6.8.10

No permission to download
Welcome to SeoBeGood
Explore seobegood.com for free access to premium themes, plugins, scripts, and digital resources. Join a thriving community of developers and enthusiasts today!
Register now!
6.8.10
*Release Date 10th September 2026*
- Security - ACF now validates that uploaded PDF files begin with the standard `%PDF-` header before further processing, rejecting files that do not match the expected format
- Security - The Relationship, Post Object, Image, Gallery, and File fields now enforce WordPress read permissions on referenced posts and attachments when returned in REST API responses
- Security - ACF now verifies both preview context and the caller's edit capability before substituting revision data when field values are retrieved for a post
- Security - The `_acf_form` token used by frontend forms now expires and is bound to its issuing render, and `acf_encrypt()` / `acf_decrypt()` gain an optional `$context` argument for domain separation between token uses
- Security - ACF now consistently runs field validation on frontend form submissions containing field data, ensuring required-field checks and custom `acf/validate_value` filters cannot be circumvented
- Security - ACF's REST API schema no longer discloses per-object field-group configuration in OPTIONS requests to callers who lack read permission on the target object
- Security - The User field AJAX endpoint now validates that the request nonce was created for a User field
6.8.7
*Release Date 4th August 2026*
- Security - ACF Image and Gallery fields now enforce server-side validation to accept only image files
- Security - The `path` attribute of registered ACF Blocks is now protected from being overridden by client-supplied block data
- Security - ACF's `acf_encrypt()` and `acf_decrypt()` helpers now authenticate encrypted values with an HMAC and no longer fall back to base64 encoding when OpenSSL is unavailable
- Security - ACF's comment, user, and options page form save handlers now only save values for fields whose field groups are assigned to the current save context
- Security - The Post Object, Page Link, and Relationship field AJAX search queries now enforce WordPress read permissions, preventing unauthenticated visitors from seeing non-public post statuses or post types
- Security - The User field now returns only user IDs in REST API responses to requesters without the `list_users` capability, preventing unauthenticated visitors from seeing user email addresses

Members online

No members online now.

Latest posts

Trending content

Forum statistics

Threads
1,812
Messages
2,527
Members
113
Latest member
johnsmith2035