Skip to:
Content
Pages
Categories
Search
Top
Bottom

Search Results for '\"wordpress\'

Viewing 25 results - 1 through 25 (of 26,984 total)
  • Author
    Search Results
  • Fixed in r7845 for trunk and r7846 for the 2.6 branch.

    @chefranov, thank you again for the excellent report, the clear diagnosis, and for being awesome. That makes three thank-yous, all well deserved! 🙌

    Thanks again, @chefranov, for another detailed report and for the clear analysis and suggested fix. You were exactly right.

    This is now fixed in trunk in https://bbpress.trac.wordpress.org/changeset/7841 and backported to the 2.6 branch in https://bbpress.trac.wordpress.org/changeset/7842, with regression coverage. The fix is targeted for bbPress 2.6.20 and 2.7.

    I really appreciate your continued help finding and documenting these issues.

    Hi @sbask,

    I confirmed that this is a regression in bbPress 2.6.19. That release changed the nonce generated for subscription links. The bundled bbPress theme package accepts both formats, but third-party theme packages such as GD Quantum Theme can reject the new format.

    I restored compatibility in trunk and the 2.6 maintenance branch, with regression coverage for both formats. The fix is scheduled for bbPress 2.6.20:

    https://bbpress.trac.wordpress.org/ticket/3711

    Please accept our sincere apologies for the mix-up, and for the extra work and delay this caused you. Thank you for reporting it and for following up.

    #250233

    Thanks for the detailed report, @chefranov. You were right: bbPress was sending Akismet the formatted post count, which was truncated when the count reached 1,000.

    I’ve committed the fix to trunk (r7839) and the 2.6 maintenance branch (r7840), with regression tests for the count boundary and anonymous posts. It will be included in bbPress 2.6.20.

    The ticket is https://bbpress.trac.wordpress.org/ticket/3709. Thanks again for catching this!

    Yevhen Chefranov
    Participant

    bbp_get_reply_class() passes the boolean true as the topic ID when it asks for the reply position. It only works because bbp_get_topic_id() ignores a non-numeric value and falls back to the topic of the current loop. Outside a topic’s own reply loop, that fallback can be a different topic, and the position is looked up in the wrong one.

    Environment

    • bbPress 2.6.19
    • WordPress 7.1.2
    • PHP 8.2

    Where

    includes/replies/template.php, line 2365:

    $reply_pos = bbp_get_reply_position( $reply_id, true );

    The signature is bbp_get_reply_position( $reply_id = 0, $topic_id = 0 ). Two lines above, the function already has the correct value:

    $topic_id  = bbp_get_reply_topic_id( $reply_id );

    What happens

    For a reply whose menu_order is still 0 (position never stored), bbp_get_reply_position() calls bbp_get_topic_id( true ). true is not numeric, so bbp_get_topic_id() goes through its fallbacks: the topic loop, the search loop, the current single topic, and so on.

    • In a topic’s own reply loop this happens to be the right topic, so the bug is hidden.
    • When replies of one topic are listed while another topic is the current one, for example a list of replies rendered on a single topic page, the position is computed with bbp_get_reply_position_raw() against the wrong topic. The reply is not among that topic’s children, so the position is 0. It is not stored, and the same query runs again on the next call.

    The visible result is a wrong bbp-reply-position-N class, plus a wasted child-ID query, which on a large topic loads every reply ID of that topic.

    Suggested fix

    $reply_pos = bbp_get_reply_position( $reply_id, $topic_id );
    #250207
    Yevhen Chefranov
    Participant

    The Akismet integration reports the wrong post count for any author with 1,000 or more posts. The formatted count (for example '1,309') is cast to int, which gives 1. Akismet then receives an experienced member as someone with a single post.

    Environment

    • bbPress 2.6.19
    • WordPress 7.1.2
    • PHP 8.2

    Where

    BBP_Akismet::check_post() in includes/extend/akismet.php, line 115:

    $user_data['total_posts'] = (int) bbp_get_user_post_count( $post_data['post_author'] );

    The value is then sent to Akismet as comment_total (line 162).

    Cause

    Without the second argument ($integer = true), bbp_get_user_post_count() runs through the bbp_get_user_post_count filter. bbp_number_format is hooked to that filter in includes/core/filters.php (line 267), so the function returns a formatted string. Casting that string to int stops at the thousands separator:

    (int) '1,309'  // 1
    (int) '12,045' // 12

    With a locale that uses a space or a non-breaking space as the separator, the result is the same.

    Impact

    Every new topic or reply from an author with 1,000+ posts is checked by Akismet with a post total of 1–999 instead of the real number. The real number is the part of the user history that most separates a long-standing member from a fresh spam account, so the most active members are the ones most likely to be judged worse than they should be. There is no error or notice; the value is just wrong.

    Steps to reproduce

    1. Activate Akismet, so bbPress loads its integration.
    2. Use an account whose _bbp_reply_count + _bbp_topic_count user meta add up to 1,000 or more.
    3. Post a reply and inspect the request sent to Akismet (for example via the bbp_akismet_check_post filter): comment_total is the digits before the first separator, not the real count.

    Suggested fix

    $user_data['total_posts'] = bbp_get_user_post_count( $post_data['post_author'], true );

    The (int) cast is then unnecessary, since the _int filter path already returns an integer.

    Yevhen Chefranov
    Participant

    Opening a topic for editing in wp-admin (post.php?post=ID&action=edit) fails with a fatal error if the topic has 1,000 or more replies. The “Replies” meta box does not render, and the rest of the edit screen is cut off at that point.

    Environment

    • bbPress 2.6.19
    • WordPress 7.1.2
    • PHP 8.2

    Error

    Uncaught TypeError: number_format(): Argument #1 ($num) must be of type int|float, string given
    in wp-includes/functions.php:428
    
    #0 number_format('2,503', 0, ',', ' ')                    wp-includes/functions.php:428
    #1 number_format_i18n('2,503')                            wp-admin/includes/class-wp-list-table.php:1051
    #2 WP_List_Table->pagination('top')                       bbpress/includes/admin/classes/class-bbp-topic-replies-list-table.php:314
    #3 BBP_Topic_Replies_List_Table->display_tablenav('top')  ...:272
    #4 BBP_Topic_Replies_List_Table->display()                bbpress/includes/admin/metaboxes.php:641
    #5 bbp_topic_replies_metabox(WP_Post, array)

    Cause

    In BBP_Topic_Replies_List_Table::prepare_items() (includes/admin/classes/class-bbp-topic-replies-list-table.php, around line 237), the total is read without the $integer flag:

    $total_items = bbp_get_topic_reply_count( $topic_id );

    Without $integer = true, the value passes through the bbp_get_topic_reply_count filter. bbp_number_format is hooked to that filter in includes/core/filters.php, so it returns a formatted string such as '2,503'. That string then goes into set_pagination_args():

    • WP_List_Table::pagination() calls number_format_i18n( $total_items ). On PHP 8 this throws a TypeError for a non-numeric string.
    • ceil( $total_items / $per_page ) is also wrong. '2,503' / 5 is evaluated as 2 / 5, so total_pages would be 1 even on PHP 7.

    Topics with fewer than 1,000 replies are not affected, because their counts have no thousands separator.

    Steps to reproduce

    1. On PHP 8.x, have a topic with 1,000 or more replies (_bbp_reply_count ≥ 1000).
    2. Open that topic in wp-admin → Topics → Edit.
    3. The “Replies” meta box shows the fatal error above.

    Suggested fix

    Request the integer count:

    $total_items = bbp_get_topic_reply_count( $topic_id, true );

    Workaround (until fixed; restricted to the topic edit screen):

    add_action( 'load-post.php', function () {
        if ( ( $GLOBALS['typenow'] ?? '' ) !== bbp_get_topic_post_type() ) {
            return;
        }
        // Runs after bbp_number_format (priority 10) and strips the separator.
        add_filter( 'bbp_get_topic_reply_count', function ( $count ) {
            return (int) preg_replace( '/\D+/', '', (string) $count );
        }, 20 );
    } );
    #250059

    Hey everyone! bbPress 2.6.19 is out. This is a security and maintenance release, so if you’re running bbPress, please update your site when you can. Sooner is better. 🙂

    Much of the work in this release makes sure private and password-protected forum content stays where it belongs. We also tightened a few moderation and forum-role checks and fixed issues with BuddyPress, imports, emails, and reply positioning.

    You can read more in the release announcement and upgrade notes. Download bbPress 2.6.19 from WordPress.org, or update right from your WordPress dashboard.

    Thanks to thewindghost, ngonhuy, and moltenbit for responsibly reporting issues, and to everyone who helped review and test this release!

    #249913

    In reply to: Image uploads

    Robin W
    Moderator

    I haven’t looked at this one for several years, so no idea if it works or is any good

    Inline Image Upload for BBPress

    Danishsard
    Participant

    I’ll test soon to see if it works—specifically, whether the password changes to the corresponding WordPress hash when someone logs in. Or does it work differently now?

    Robin W
    Moderator

    Have you looked at

    bbp style pack

    It has loads of features for bbpress.

    Danishsard
    Participant

    I think bbPress has huge development potential; it is also the most deeply integrated with WordPress. It would be great to see it evolve—perhaps along the lines of other forum solutions that offer comprehensive feature bundles.

    It’s a great forum platform, though highly underrated because the core package lacks extensive features. In my view, however, it holds the greatest potential to evolve into a fantastic tool for enriching WordPress sites.

    #249865
    Fabio Plugins
    Participant

    Tanks, feel free to use the free version : https://wordpress.org/plugins/fabio-ai-chatbot-lite/.

    #249858
    specialworld83
    Participant

    Introducing Aurora bbPress 1.0!

    Aurora is a modern forum template plugin developed by CodeLinSoft to completely redesign the appearance and user experience of bbPress without replacing your existing WordPress theme.

    Designed with a clean, elegant, and responsive interface, Aurora makes it easier to discover discussions, interact with other members, and build an engaging online community.

    MAIN FEATURES

    • Modern, responsive interface for desktop, tablet, and mobile.

    • Redesigned homepage with forum categories, community statistics, and active members.

    • Dedicated recent discussions page with search, filters, and topic previews.

    • Modern topic layouts with author information, discussion statistics, and an interactive timeline.

    • SCEditor WYSIWYG editor with XHTML support.

    • Integrated image and file attachments.

    • Customizable user profiles with avatars and cover images.

    • Configurable discussion badges and member rankings.

    • Automatic topic subscriptions and notifications with an unread counter and dropdown.

    • Customization options available directly from WordPress Admin.

    • Multilingual interface with 12 included languages.

    COMPATIBILITY

    Aurora works as an independent WordPress plugin, preserving the underlying bbPress discussion system and your existing WordPress theme.

    Version: 1.0

    WordPress: 6.4 or later

    PHP: 7.4 or later

    Requires: bbPress

    License: CodeLinSoft Proprietary License

    DISCOVER AURORA

    Explore its features, view the interface previews, and get the plugin from the official website:

    Aurora bbPress – Official Product Page

    Feedback, suggestions, and feature requests are welcome!

    Developed by CodeLinSoft.

    #249852
    Robin W
    Moderator

    @jgasba Thanks for posting, the original thread was old, but exactly the right place for you to add your comments.

    So the subscribe/unsubscribe features in profile refer to the user accessing the profile. So if you go into a users bbpress profile, then there is a subscriptions tab, but this is for you (as admin/keymaster in your case) to ‘also’ subscribe/unsubscribe, it does not allow you to subscribe/unsubscribe a user.

    You can manage subscriptions using the bbp style pack additional plugin (which has lots of other stuff you can amend in bbpress)

    so Install

    bbp style pack

    once activated go to

    dashboard>settings>bbp style pack>Subscription Management
    and activate, and follow the explanation there of how to manage subscitions for users, forums and topics

    #249831
    Robin W
    Moderator

    Thanks for your support ticket in the style pack plugin.

    I have done an update which should be live in a few hours – WordPress are now delaying releases so that moderators and security scanners can review changes before they reach users.

    If anyone needs a release quicker, you can download from the WordPress site

    bbp style pack

    Sorry to hear about all of that.

    I’ve fixed the phpBB importer, and I’m quickly auditing the other importers for similar problems.

    See: https://bbpress.trac.wordpress.org/ticket/3683

    2.6.18 will include these fixes.

    #249817

    bbPress 2.6.17 is a security and maintenance release that improves permissions, private content handling, subscription notifications, moderation workflows, and forum counts. Everyone running bbPress should update as soon as possible.

    Read the release announcement and get bbPress 2.6.17 from WordPress.org.

    #249778
    Robin W
    Moderator

    Install

    bbp style pack

    once activated go to

    dashboard>settings>bbp style pack>Topic/Reply Display

    and items 17, 18 & 19 will let you set what you want

    Peter
    Participant
    #249719
    stracy2
    Participant

    Is someone working a patch or fix?

    Wordfence gives alerts to this issue.

    patchstack, credited with finding this CVE:

    States “This security issue has a low severity impact and is unlikely to be exploited.” and has no vPatch. Here is that report.

    #249711
    crzyhrse
    Participant

    bbPress <= 2.6.14 – Missing Authorization
    Wordfence Intelligence > Vulnerability Database > bbPress <= 2.6.14 – Missing Authorization
    5.3
    Missing Authorization
    CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
    CVE CVE-2026-74010
    CVSS 5.3 (Medium)
    Publicly Published August 31, 2026
    Last Updated September 1, 2026
    Researcher Ananda Dhakal
    Description
    The bbPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.6.14. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

    References
    vdp.patchstack.com

    #249420
    nooreshaal
    Participant

    Thanks for sharing this fix. While working on Instatroids, we’ve also encountered similar WordPress embed issues caused by plugin conflicts. This solution is simple and helpful.

    #249344
    Robin W
    Moderator

    You can use shortcodes instead

    Shortcodes

    There are also additional ones with filters in

    bbp style pack

    once activated go to

    dashboard>settings>bbp style pack>shortcodes

    #249327

    In reply to: uses_utf8 problem

    pentatonicfunk
    Participant
    
    FILE: /bbpress/includes/common/formatting.php
    ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
    FOUND 0 ERRORS AND 2 WARNINGS AFFECTING 2 LINES
    ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
     810 | WARNING | seems_utf8() has been deprecated since WordPress version 6.9.0. Use wp_is_valid_utf8() instead. (WordPress.WP.DeprecatedFunctions.seems_utf8Found)
     811 | WARNING | Function utf8_encode() is deprecated since PHP 8.2; Use mb_convert_encoding(), UConverter::transcode() or iconv instead (PHPCompatibility.FunctionUse.RemovedFunctions.utf8_encodeDeprecated)
    ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
    
Viewing 25 results - 1 through 25 (of 26,984 total)
Skip to toolbar