Security update that addresses a vulnerability reported to us by security researcher Francesco Carlucci. It also includes a fix for broken Gutenberg blocks in the latest version of WordPress (6.5+) when using Oxygen The security issue we have addressed is a privilege escalation vulnerability that would allow a user with “contributor” or higher permissions to escalate their privileges to an admin (CVE-2024-4662). This issue impacts anyone that has granted untrusted users Contributor+ access to their WordPress website. It does not affect you if you do not have Contributor+ users on your WordPress website. This issue can only be exploited by a Contributor+ user At this time there are no known instances of this vulnerability being exploited in the wild
ENHANCEMENT - Updated CodeMirror to CodeMirror 6 ENHANCEMENT - Added auto-complete for CSS/JS/HTML in Oxygen code editors ENHANCEMENT - Enabled code folding for Oxygen code editors ENHANCEMENT - Enabled full search/replace for Oxygen code editors ENHANCEMENT - Added "Mixed Code" view for Code Blocks to show PHP, JS, and CSS editors at the same time (like CodePen) ENHANCEMENT - Add a "Mixed View" button to the individual code editor views for the Code Block (#5044) ENHANCEMENT - Made Code Block code get applied on save (#5091) TWEAK - Update default YouTube video (#5087) TWEAK - Changed default CodeMirror theme (#5095) TWEAK - Make all Easy Posts presets have "default" query by default (#5098) TWEAK - Remove theme chooser in Stylesheets editor. It now inherits the theme chosen in Oxygen (#5083) TWEAK - Removed some CodeMirror themes that were terrible (#5046) FIX - Site Navigation now outputs the proper target attribute as designated in WordPress menu settings (#5149)
Subscribe to get access to unlimited premium items from our community of global authors and developers.
Last update:
26-06-2024 10:51 PM
Published:
22-06-2024 06:02 PM
Version:
Category: