So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer's plug-in using the developer's own code, ostensibly as retribution for a security issue that the developer had already fixed.
https://www.advancedcustomfields.com/blog/acf-6-3-8-security...What am I missing?
This release fixes a separate security vulnerability from the original update.
Can anyone else prove this security vulnerability actually existed?
It doesn't matter. Matt didn't have the right to hijack ACF.
I'm not on Matt's side, but anyone has the right to fork a GPL project and call it something else.
This is not a fork. He stole the original project plugin space, its reviews, download statistics, SEO traffic, etc. It has nothing to do with GPL.