version 4.25.2 ( updated 06-12-2024 )
- Security Update: Fixed a stored XSS vulnerability that made it possible for users with Contributor role or above to insert JavaScript code onto the page via the Divi Builder Gallery module's shortcode. Props to Ngô Thiên An (ancorn_) for the responsible disclosure.
- Hide Role Editor settings related to Theme Options, Theme Builder, Theme Customizer, Divi Library, and Support Center for roles without edit_theme_options capability. By default, this changes effected Editor, Author, and Contributor roles, unless they have edit_theme_options capability.
- Fixed a PHP fatal error that occurred in some cases when importing Theme Builder layouts.
- Fixed a PHP notice that occurred during Social Media module Twitter to X migration.
- Fixed a PHP warning (Undefined array key 0).