WordPress Forks ACF into Secure Custom Fields to Address Security Flaws

The WordPress security team has announced the creation of Secure Custom Fields (SCF), a fork of the Advanced Custom Fields (ACF) plugin. This move addresses significant security vulnerabilities and removes commercial upsells that were part of ACF. Site owners using ACF need to take action to ensure their sites remain secure.

What is Secure Custom Fields?

Secure Custom Fields is designed to provide a safer alternative to ACF by eliminating security risks and commercial upsells. This plugin is now available for users who want to maintain a secure environment for their WordPress sites.

How to Update to Secure Custom Fields?

For those using WordPress.org’s update service, switching to Secure Custom Fields is straightforward. If auto-updates are enabled, the transition from ACF to SCF will occur automatically. Alternatively, site owners can manually uninstall ACF and activate Secure Custom Fields from the plugin directory.

Why Transition to Secure Custom Fields?

Transitioning to Secure Custom Fields is crucial to avoid potential security threats associated with ACF. By using SCF, site owners can ensure they are protected against vulnerabilities that may compromise their sites.

What About ACF Updates?

WP Engine has introduced its own update solution for ACF, but the WordPress security team advises against using it due to ongoing security issues. Uninstalling ACF and activating Secure Custom Fields is the recommended course of action for site owners.

Frequently Asked Questions

What is Secure Custom Fields?

Secure Custom Fields is a new plugin forked from Advanced Custom Fields to address security issues and remove commercial upsells.

How do I switch from ACF to Secure Custom Fields?

Sites using WordPress.org’s update service can switch to Secure Custom Fields, which will automatically replace ACF if auto-updates are enabled.

What are the security issues with ACF?

The security issues with ACF prompted the creation of Secure Custom Fields to ensure user safety.

Can I still use ACF after this announcement?

While you can still use ACF, it is recommended to uninstall it and activate Secure Custom Fields to avoid security risks.

What is WP Engine’s role in ACF updates?

WP Engine has implemented its own update solution for ACF, but the WordPress security team recommends switching to Secure Custom Fields instead.