JetEngine - Dynamische Inhalte mit Elementor anhängen und bearbeiten

JetEngine - Dynamische Inhalte mit Elementor anhängen und bearbeiten 3.8.13

Keine Berechtigung zum Herunterladen
- ADD. Admin UI. Add `Add new` and `Back to list` buttons to base admin instance pages;
- ADD: JetFormBuilder. Add Delete Custom Content Type Item action;
- UPD: Admin UI. Improve conditional visiblity handling for the fields inside meta boxes;
- UPD: Listing Grid. Change default listing template structure to use Container for Elementor listing templates;
- FIX: Admin UI. Issue with meta boxes styling on the Woo product pages after latest WP/Woo updates;
- FIX: Query Builder. Correctly process WC product query date clauses;
- FIX: Elementor preview. Ensure WP block Columns styles are enqueued in preview mode;
- FIX: Elementor dynamic tag fatal on profile pages when custom field contains non-scalar object;
- FIX: Dynamic Calendar. Calendar-related AJAX requests now sends calendar type for multiday calendars to allow proper server-side rendering and caching.
- ADD: Profile Builder. Allow selecting multiple roles for "Show menu for the role" option in "Profile menu";
- ADD: Listing grid. Add server-side signature for filtered query to prevent client-side tampering of listing arguments;
- UPD: CCT. Allow to delete CCT item when its related single post is permanently deleted;
- FIX: Query Builder. Avoid PHP warnings when condition "field" is non-string and ensure proper sanitization;
- FIX: Query Builder. Label dedicated relation tables with relation names in the SQL table selector;
- FIX: Dynamic Field + Gallery Slider. Set auto height by default;
- FIX: Dynamic Field. Reduce redundant inner wrapper and optimize DOM output;
- FIX: `[jet_engine]` shortcode. Sanitize output to prevent XSS;
- FIX: Components. Preview styles in the Block editor;
- FIX: Components. Prevent PHP warning when using Dynamic Field with empty value and no fallback;
- FIX: Replace unsafe `maybe_unserialize` usage with safe unserialize helpers across all components where it was needed.
- FIX: Query Builder. Advanced SQL query. Rework macros sanitizing to effectively prevent potential SQL-injections but avoid false-positives.
- FIX: Legacy Forms. Add data escaping/sanitization where it was missed;
- FIX: Use safe unserialization for any serialized data, which can came from the untrusted sources.
- FIX: Query Builder. Advanced SQL Query. More strict applied macros sanitizing to avoid SQL vulnerabilities through publicy allowed macros inputs;
- FIX: Data Stores. Reset datastore item counters when clearing Data Stores and CCT stores;
- FIX: Maps Listings. Improve escaping and accessibility for Location & Distance filter (aria labels, escaped attributes and option output);
- FIX: Components & Elementor views. Background dynamic image handling and Atomic Editor style inlining for components built with Elementor;
- FIX: Dynamic Visibility. Block editor error when using Dynamic Visibility;
- FIX: Maps Listings. Location Input default value for Maps Listings filter block;
- FIX: Angie compatibility;
- FIX: Blocks views. Editor styling issues after WordPress 7.0 update;
- FIX: Dynamic image preview for specific sizes in Listings — fall back to available thumbnail when requested size is missing;
- FIX: Listings. improve unique ID generation for listing objects to reduce collisions and make IDs stable per content object
- FIX: WooCommerce Product Image dynamic tag now uses configured fallback when no current product is available.
- FIX: Query Builder. SQL query type. More strict sanitizng of the input parmaters to prevent SQL injections.
- FIX: More strict sanitization of custom table queries to prevent potential SQL injections in some cases (appears as combination of the some backend CPT config and appropriate front-end setup);
- FIX: Legacy forms. Santizie status-related query parameters to prevent XSS vulnerability through the form status parmeter;
- FIX: Sanitize URL form fields and listing URLs using JetEngine URL schemes;
- FIX: Custom COntent Types. Only unserialize array-backed fields when reading items to avoid converting unauthorized serialized strings into real PHP objects.
- ADD: Meta boxes. Field layout option (Inline/Stacked);
- UPD: CCT + Query Builder. Intersect _ID IN values from initial query and existing filters;
- FIX: Dynamic Calendar. Normalize event day bounds using site timezone to fix missing/incorrect multi-day rendering;
- FIX: Maps Listings. Marker REST access — add source-aware publish/access checks and handle unknown sources;
- FIX: Maps Listings. Apply JetSmartFilters currentQuery (jsf_query) for map popup requests;
- FIX: Glossaries. Fix handling of "0" custom checkbox values in glossary;
- FIX: Meta Boxes. Isolate WC variation meta field names to avoid collisions with parent product fields in variation meta box;
- FIX: Adjust Swiper pagination spacing to improve vertical gap and avoid overlap in listings/pagers;
- FIX: Potential XSS vulnerability in legacy forms module and PayPal handler;
- FIX: Potential PHP object injection when unsafe serialized data is stored into the post data;
- FIX: Potential SQL injection with some query types using navigation parameters for the listing grid AJAX handler.
- FIX: Query Results Count macro doesn't update count after filtering
- FIX: Elementor responsive is not working on Dynamic Field widget
- FIX: More strict snitizing search parameters for public CCT Rest API endpoints.
Zurück
Oben