= 2025.6 =
- Security fix: Vulnerability Title: Advanced iFrame <= 2025.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CVE ID: CVE-2025-6987 was fixed.
- New: Tested with WordPress 6.8.2
- New: advanced iframe has a new domain:
https://www.advanced-iframe.com. All links in the plugin where updated and checked.
- New:
https://www.advanced-iframe.com is live now. Everything from
www.tinywegballery.com/blog was moved. Also a new menu structure was introduced.
- New: Edge was added as setting in the browser detection.
- New: Standalone version is now also available in the freemius version.
- New: Standalone examples where reworked and old links removed.
- New: Standalone version is now even easier to setup because the site_url handling was rewritten and the default should work now even better.
- New: Standalone version now also uses jQuery 3.7.1 like WordPress does.
- New: The freemius section documentation was improved based on user feedback.
- New: No 10.000 hit limit anymore. The powered by text is now removed automatically when you OPT-IN or if you disable it.
- New: Updated Freemius to 2.12.1
- Fix: Add iframe url as param: Same domain with hash" was broken because one of the last security fixes was too tight. Now it works fine again:
https://www.advanced-iframe.com/adv...demo/add-iframe-url-as-param-same-domain-hash
- Fix: add_iframe_url_as_param_direct was not working anymore because of a wrong security check. Now
https://www.advanced-iframe.com/advanced-iframe/advanced-iframe-pro-demo/add-iframe-params-to-parent works fine for the remove and same domain again.
- Fix: documentation of the external workaround was improved.
- Fix: When switching between free and pro a notice about unwanted characters was shown. This was a notice because both plugin where active for a small amount of time. This is solved now.
- Fix: Users often use false in hide_part_of_iframe and a message was shown. Users contacted the advanced iframe team to solve this. Now this setting is simply ignored.
- Removed: iframe_zoom_ie8 was removed and all the code that comes with it as ie8 browser is not used anymore.
- Removed: "Special case sub domain" section was removed as it was only containing the removal info text for one year.