Search Results for '\"wordpress\'
-
Search Results
-
bbp_get_reply_class()passes the booleantrueas the topic ID when it asks for the reply position. It only works becausebbp_get_topic_id()ignores a non-numeric value and falls back to the topic of the current loop. Outside a topic’s own reply loop, that fallback can be a different topic, and the position is looked up in the wrong one.Environment
- bbPress 2.6.19
- WordPress 7.1.2
- PHP 8.2
Where
includes/replies/template.php, line 2365:$reply_pos = bbp_get_reply_position( $reply_id, true );
The signature is
bbp_get_reply_position( $reply_id = 0, $topic_id = 0 ). Two lines above, the function already has the correct value:$topic_id = bbp_get_reply_topic_id( $reply_id );
What happens
For a reply whose
menu_orderis still 0 (position never stored),bbp_get_reply_position()callsbbp_get_topic_id( true ).trueis not numeric, sobbp_get_topic_id()goes through its fallbacks: the topic loop, the search loop, the current single topic, and so on.- In a topic’s own reply loop this happens to be the right topic, so the bug is hidden.
- When replies of one topic are listed while another topic is the current one, for example a list of replies rendered on a single topic page, the position is computed with
bbp_get_reply_position_raw()against the wrong topic. The reply is not among that topic’s children, so the position is 0. It is not stored, and the same query runs again on the next call.
The visible result is a wrong
bbp-reply-position-Nclass, plus a wasted child-ID query, which on a large topic loads every reply ID of that topic.Suggested fix
$reply_pos = bbp_get_reply_position( $reply_id, $topic_id );
The Akismet integration reports the wrong post count for any author with 1,000 or more posts. The formatted count (for example
'1,309') is cast toint, which gives1. Akismet then receives an experienced member as someone with a single post.Environment
- bbPress 2.6.19
- WordPress 7.1.2
- PHP 8.2
Where
BBP_Akismet::check_post()inincludes/extend/akismet.php, line 115:$user_data['total_posts'] = (int) bbp_get_user_post_count( $post_data['post_author'] );
The value is then sent to Akismet as
comment_total(line 162).Cause
Without the second argument (
$integer = true),bbp_get_user_post_count()runs through thebbp_get_user_post_countfilter.bbp_number_formatis hooked to that filter inincludes/core/filters.php(line 267), so the function returns a formatted string. Casting that string tointstops at the thousands separator:(int) '1,309' // 1 (int) '12,045' // 12
With a locale that uses a space or a non-breaking space as the separator, the result is the same.
Impact
Every new topic or reply from an author with 1,000+ posts is checked by Akismet with a post total of 1–999 instead of the real number. The real number is the part of the user history that most separates a long-standing member from a fresh spam account, so the most active members are the ones most likely to be judged worse than they should be. There is no error or notice; the value is just wrong.
Steps to reproduce
- Activate Akismet, so bbPress loads its integration.
- Use an account whose
_bbp_reply_count+_bbp_topic_countuser meta add up to 1,000 or more. - Post a reply and inspect the request sent to Akismet (for example via the
bbp_akismet_check_postfilter):comment_totalis the digits before the first separator, not the real count.
Suggested fix
$user_data['total_posts'] = bbp_get_user_post_count( $post_data['post_author'], true );
The
(int)cast is then unnecessary, since the_intfilter path already returns an integer.Opening a topic for editing in wp-admin (
post.php?post=ID&action=edit) fails with a fatal error if the topic has 1,000 or more replies. The “Replies” meta box does not render, and the rest of the edit screen is cut off at that point.Environment
- bbPress 2.6.19
- WordPress 7.1.2
- PHP 8.2
Error
Uncaught TypeError: number_format(): Argument #1 ($num) must be of type int|float, string given in wp-includes/functions.php:428 #0 number_format('2,503', 0, ',', ' ') wp-includes/functions.php:428 #1 number_format_i18n('2,503') wp-admin/includes/class-wp-list-table.php:1051 #2 WP_List_Table->pagination('top') bbpress/includes/admin/classes/class-bbp-topic-replies-list-table.php:314 #3 BBP_Topic_Replies_List_Table->display_tablenav('top') ...:272 #4 BBP_Topic_Replies_List_Table->display() bbpress/includes/admin/metaboxes.php:641 #5 bbp_topic_replies_metabox(WP_Post, array)Cause
In
BBP_Topic_Replies_List_Table::prepare_items()(includes/admin/classes/class-bbp-topic-replies-list-table.php, around line 237), the total is read without the$integerflag:$total_items = bbp_get_topic_reply_count( $topic_id );
Without
$integer = true, the value passes through thebbp_get_topic_reply_countfilter.bbp_number_formatis hooked to that filter inincludes/core/filters.php, so it returns a formatted string such as'2,503'. That string then goes intoset_pagination_args():WP_List_Table::pagination()callsnumber_format_i18n( $total_items ). On PHP 8 this throws aTypeErrorfor a non-numeric string.ceil( $total_items / $per_page )is also wrong.'2,503' / 5is evaluated as2 / 5, sototal_pageswould be 1 even on PHP 7.
Topics with fewer than 1,000 replies are not affected, because their counts have no thousands separator.
Steps to reproduce
- On PHP 8.x, have a topic with 1,000 or more replies (
_bbp_reply_count≥ 1000). - Open that topic in wp-admin → Topics → Edit.
- The “Replies” meta box shows the fatal error above.
Suggested fix
Request the integer count:
$total_items = bbp_get_topic_reply_count( $topic_id, true );
Workaround (until fixed; restricted to the topic edit screen):
add_action( 'load-post.php', function () { if ( ( $GLOBALS['typenow'] ?? '' ) !== bbp_get_topic_post_type() ) { return; } // Runs after bbp_number_format (priority 10) and strips the separator. add_filter( 'bbp_get_topic_reply_count', function ( $count ) { return (int) preg_replace( '/\D+/', '', (string) $count ); }, 20 ); } );Topic: bbPress 2.6.19 is out!
Hey everyone! bbPress 2.6.19 is out. This is a security and maintenance release, so if you’re running bbPress, please update your site when you can. Sooner is better. 🙂
Much of the work in this release makes sure private and password-protected forum content stays where it belongs. We also tightened a few moderation and forum-role checks and fixed issues with BuddyPress, imports, emails, and reply positioning.
You can read more in the release announcement and upgrade notes. Download bbPress 2.6.19 from WordPress.org, or update right from your WordPress dashboard.
Thanks to thewindghost, ngonhuy, and moltenbit for responsibly reporting issues, and to everyone who helped review and test this release!
Introducing Aurora bbPress 1.0!
Aurora is a modern forum template plugin developed by CodeLinSoft to completely redesign the appearance and user experience of bbPress without replacing your existing WordPress theme.
Designed with a clean, elegant, and responsive interface, Aurora makes it easier to discover discussions, interact with other members, and build an engaging online community.
MAIN FEATURES
• Modern, responsive interface for desktop, tablet, and mobile.
• Redesigned homepage with forum categories, community statistics, and active members.
• Dedicated recent discussions page with search, filters, and topic previews.
• Modern topic layouts with author information, discussion statistics, and an interactive timeline.
• SCEditor WYSIWYG editor with XHTML support.
• Integrated image and file attachments.
• Customizable user profiles with avatars and cover images.
• Configurable discussion badges and member rankings.
• Automatic topic subscriptions and notifications with an unread counter and dropdown.
• Customization options available directly from WordPress Admin.
• Multilingual interface with 12 included languages.
COMPATIBILITY
Aurora works as an independent WordPress plugin, preserving the underlying bbPress discussion system and your existing WordPress theme.
Version: 1.0
WordPress: 6.4 or later
PHP: 7.4 or later
Requires: bbPress
License: CodeLinSoft Proprietary License
DISCOVER AURORA
Explore its features, view the interface previews, and get the plugin from the official website:
Aurora bbPress – Official Product Page
Feedback, suggestions, and feature requests are welcome!
Developed by CodeLinSoft.
Topic: bbPress 2.6.17 is out!
bbPress 2.6.17 is a security and maintenance release that improves permissions, private content handling, subscription notifications, moderation workflows, and forum counts. Everyone running bbPress should update as soon as possible.
Read the release announcement and get bbPress 2.6.17 from WordPress.org.
Can you please help with an update to fix this security issue?
https://patchstack.com/database/wordpress/plugin/bbpress/vulnerability/wordpress-bbpress-plugin-2-6-14-broken-access-control-vulnerabilitybbPress <= 2.6.14 – Missing Authorization
Wordfence Intelligence > Vulnerability Database > bbPress <= 2.6.14 – Missing Authorization
5.3
Missing Authorization
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE CVE-2026-74010
CVSS 5.3 (Medium)
Publicly Published August 31, 2026
Last Updated September 1, 2026
Researcher Ananda Dhakal
Description
The bbPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.6.14. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.References
vdp.patchstack.com