Security
- Fixed a reflected XSS vulnerability in the field-suggestion AJAX endpoint (reported via Patchstack)
- Hardened the wpv_suggest_* AJAX endpoints against XSS and information disclosure
Compatibility
- Raised the minimum PHP version to 7.4 and cleared deprecation notices on PHP 8.2–8.5
- Fixed “translation loaded too early” notices on WordPress 6.7+
Fixed compatibility with WP Rocket’s CDN URL rewriting
- Fixed a Gutenberg editor crash affecting all Toolset blocks on WordPress 6.5+
Fixes
- Fixed Toolset blocks freezing the editor when used inside synced patterns
- Social Share block: replaced the Twitter logo with X and added WhatsApp as a network
- Fixed the taxonomy dependent-search filter not being applied
- Fixed nested shortcodes leaking as placeholders in View attributes