| @@ -1,10 +1,10 @@ | ||
| 1 | 1 | === wpForo Forum === |
| 2 | 2 | Contributors: gVectors Team |
| 3 | 3 | Tags: forum, forums, forum plugin, bbpress, community |
| 4 | 4 | Requires at least: 5.2 |
| 5 | -Tested up to: 7.0 | |
| 6 | -Stable tag: 3.1.2 | |
| 5 | +Tested up to: 7.1 | |
| 6 | +Stable tag: 3.1.6 | |
| 7 | 7 | Requires PHP: 7.1 |
| 8 | 8 | License: GPLv2 or later |
| 9 | 9 | License URI: https://www.gnu.org/licenses/gpl-2.0.html |
| 10 | 10 | |
| @@ -233,8 +233,40 @@ | ||
| 233 | 233 | - After the update, please flush Redis Object Cache if you have this cache enabled |
| 234 | 234 | |
| 235 | 235 | [wpForo Forum v3.0 Release Summary](https://wpforo.com/community/wpforo-announcements/wpforo-3-0-is-released/) |
| 236 | 236 | |
| 237 | + | |
| 238 | + | |
| 239 | += wpForo Forum 3.1.6 | 18.09.2026 = | |
| 240 | + | |
| 241 | +* Compatibility: WordPress 7.1 | |
| 242 | +* Security: Fixed PHP Object Injection vulnerability in custom form fields | |
| 243 | +* Security: Fixed Guest Post Takeover vulnerability allowing guest topics and posts to be edited via a forged ownership cookie | |
| 244 | +* Security: Fixed Stored XSS vulnerability in topic tags, exposed on topic pages, forum listings, the Tags page and search results | |
| 245 | +* Security: Fixed AI credit exhaustion via rate limit manipulation | |
| 246 | +* Security: Hardened profile field deserialization against crafted payloads, including a denial of service on the registration form | |
| 247 | +* Added: Frequency, A-Z and Z-A sort controls on the Tags page | |
| 248 | +* Optimized: Forum cache file limit is now calculated from the online members count, with oldest-first cleanup instead of a full cache wipe | |
| 249 | +* Fixed: Tag links no longer break for tags containing &, # or + characters | |
| 250 | + | |
| 251 | + | |
| 252 | += wpForo Forum 3.1.5 | 16.08.2026 = | |
| 253 | + | |
| 254 | +* AI New: Video tutorials and getting started steps on AI Features page | |
| 255 | +* Optimized: Mark all read button database query | |
| 256 | +* Fixed: Fatal error when admin bar renders before wpForo initialization | |
| 257 | +* Fixed: first_name and last_name fields silently discarded on registration | |
| 258 | + | |
| 259 | + | |
| 260 | += wpForo Forum 3.1.3/3.1.4 | 23.07.2026 = | |
| 261 | + | |
| 262 | +* Security: Fixed access control bypass in widget AJAX handlers (Recent Topics, Recent Posts, Online Members) | |
| 263 | +* Security: Fixed missing view_access() checks in AI translation and summarization endpoints | |
| 264 | +* Security: Fixed AI search indexing unapproved forum posts | |
| 265 | +* Security: Fixed WordPress content indexer ignoring password-protected posts | |
| 266 | +* Security: Fixed XSS vulnerability in AI-generated HTML responses | |
| 267 | +* Security: Fixed mass assignment bypass in profile and registration forms | |
| 268 | +* Fixed: Missing itemprop name attribute in Members breadcrumb | |
| 237 | 269 | |
| 238 | 270 | |
| 239 | 271 | = wpForo Forum 3.1.2 | 11.07.2026 = |
| 240 | 272 | |