bbPress 2.6.12 is a minor release that fixes 1 security issue and 1 small bug.
The security issue was responsibly disclosed via the WordPress HackerOne bounty program. It does not appear to be actively exploited, and specifically targets: single-site WordPress installations, newer than 5.3.0, with the “Membership” setting set to “Anyone can register”, and with bbPress active.
(Even if that isn’t you, you should still update bbPress to 2.6.12 anyways!)
The minor bug was a regression to the search component introduced in 2.6.11, causing search results to not be as accurate as everyone deserves for them to be. 🕵
Both of these fixes are already merged into the 2.7 development branch.
Thank you to GDragoN and mungah (via HackerOne) for your help fixing bugs, and Robin W for keeping the bbPress.org Forums squeaky clean and well-supported! I really appreciate all of y’all! 🐝