Version | Change log |
BuddyPress 4.3.0 Apr 25, 2019 |
Blogs: Fix bug that caused wp-signup.php links not to be redirected in all cases. (#6178) Templates: Add missing PHP delimiters from Nouveau template. (#8085) Templates: Fix directory filtering regression introduced in BP 4.2.0. (#8064, #8067) Security: Prevent access to activity items in hidden groups via “favorite” feature. Security: Prevent access to group join mechanism by unauthorized users. Security: Prevent replies to activity items in non-public groups by unauthorized users in Nouveau. Security: Prevent unauthorized access to message threads via AJAX query manipulation in Nouveau. Security: Prevent XSS via group names. Security: Prevent XSS in activity content. Security: Prevent privilege escalation when editing group details. Security: Prevent unauthorized read access to pending group invitations. Security: Prevent unauthorized group invitation deletion in Nouveau. |