BuddyPress 2.2.2 Released Addresses Two Potential Security Issues

BuddyPress Featured ImageBuddyPress 2.2.2 is available from the WordPress plugin directory. It fixes two potential security issues and has a few bug fixes. This is what is fixed in 2.2.2.

  • Activity: sanitize output of “Load More” link
  • Members: better nonce check on members widget
  • Core: improve filtering of wp_title

The security issues were responsibly disclosed by Todd Gibson and Justin Heideman. I jokingly asked BuddyPress lead developer, John James Jacoby, about releasing security fixes on a Friday evening. He said he’d rather be annoying than irresponsible.

https://twitter.com/JJJ/status/586708832874803200

If I used BuddyPress, I’d want security fixes as soon as they’re available. Thanks to Jacoby and the rest of the BuddyPress team for helping to keep sites safe no matter what time of day it is. You can download BuddyPress 2.2.2 from the WordPress plugin directory, or visit Dashboard – Updates in the WordPress backend.

1

One response to “BuddyPress 2.2.2 Released Addresses Two Potential Security Issues”

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Newsletter

Subscribe Via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Discover more from WP Tavern

Subscribe now to keep reading and get access to the full archive.

Continue reading