ACF security bug -> Cwicly update needed ASAP

Security researchers warn that the ‘Advanced Custom Fields’ and ‘Advanced Custom Fields Pro’ WordPress plugins, with millions of installs, are vulnerable to cross-site scripting attacks (XSS).

ACF has released a patch, but it can be installed with Cwicly update only. Any chance to get unplanned Cwicly update?

Hello @Audrius,

Thank you for the report.
1.2.9.5.8.4 includes ACF Pro 6.1.6 which fixes the vulnerability.

Cheers,

2 Likes