| @@ -1,10 +1,10 @@ | ||
| 1 | 1 | === wpForo Forum === |
| 2 | 2 | Contributors: gVectors Team |
| 3 | 3 | Tags: forum, forums, forum plugin, bbpress, community |
| 4 | 4 | Requires at least: 5.2 |
| 5 | -Tested up to: 7.0 | |
| 6 | -Stable tag: 3.1.2 | |
| 5 | +Tested up to: 7.1 | |
| 6 | +Stable tag: 3.2.0 | |
| 7 | 7 | Requires PHP: 7.1 |
| 8 | 8 | License: GPLv2 or later |
| 9 | 9 | License URI: https://www.gnu.org/licenses/gpl-2.0.html |
| 10 | 10 | |
| @@ -135,9 +135,21 @@ | ||
| 135 | 135 | |
| 136 | 136 | [Terms of Service](https://gvectors.com/terms-and-conditions/) |
| 137 | 137 | [Privacy Policy](https://gvectors.com/privacy-policy/) |
| 138 | 138 | |
| 139 | +**gVectors Addons News & License Reminders** (store.gvectors.com) | |
| 139 | 140 | |
| 141 | +If the forum administrator explicitly enables the addon news service (it is disabled by default and requires opt-in), wpForo connects to store.gvectors.com once per day to: | |
| 142 | + | |
| 143 | +* Fetch news about new addons, new features and announcements (endpoint: /news) — this request sends no site-specific data beyond standard HTTP request information | |
| 144 | +* Check for addon licenses that are close to expiration (endpoint: /at-risk-licenses) — this request sends your site address, an anonymous site identifier (an HMAC hash generated from your site domain and your WordPress security salts), and the slugs and installed versions of your gVectors addons | |
| 145 | + | |
| 146 | +No personal data, no email addresses, and no forum content is ever sent to this service. News notifications are shown as dismissible messages in the WordPress admin, and summary emails are sent by your own site (via your own mail server) to site administrators. The service can be disabled at any time from the wpForo Addons page, which stops all outbound requests immediately. | |
| 147 | + | |
| 148 | +[Terms of Service](https://gvectors.com/terms-and-conditions/) | |
| 149 | +[Privacy Policy](https://gvectors.com/privacy-policy/) | |
| 150 | + | |
| 151 | + | |
| 140 | 152 | == Installation == |
| 141 | 153 | |
| 142 | 154 | 1. Install wpForo Forum plugin in Dashboard > Plugins admin page. Then activate it. |
| 143 | 155 | 2. If you have more than 100 users wpForo forum plugin prompts you synchronize users. |
| @@ -231,10 +243,52 @@ | ||
| 231 | 243 | |
| 232 | 244 | - After the update, please delete all caches and purge CDN if you have |
| 233 | 245 | - After the update, please flush Redis Object Cache if you have this cache enabled |
| 234 | 246 | |
| 235 | -[wpForo Forum v3.0 Release Summary](https://wpforo.com/community/wpforo-announcements/wpforo-3-0-is-released/) | |
| 247 | +[wpForo Forum v3.2 Release Summary](https://wpforo.com/community/wpforo-announcements/wpforo-3-2-is-released/) | |
| 236 | 248 | |
| 249 | + | |
| 250 | + | |
| 251 | += wpForo Forum 3.2.0 | 25.09.2026 = | |
| 252 | + | |
| 253 | +* Addons Store: Purchase and manage addon licenses directly in your WordPress dashboard. No need to go to gVectors Store, purchase, then download and install. Now you can do one-click purchase, install, and update addons directly in your wpForo > Addons admin page. | |
| 254 | + | |
| 255 | + | |
| 256 | += wpForo Forum 3.1.7 | 22.09.2026 = | |
| 257 | + | |
| 258 | +* Security: Fixed Stored XSS vulnerability in some text fields | |
| 259 | +* Fixed: Infinite recursion causing fatal error and 504/508 timeouts on forum pages | |
| 260 | + | |
| 261 | += wpForo Forum 3.1.6 | 18.09.2026 = | |
| 262 | + | |
| 263 | +* Compatibility: WordPress 7.1 | |
| 264 | +* Security: Fixed PHP Object Injection vulnerability in custom form fields | |
| 265 | +* Security: Fixed Guest Post Takeover vulnerability allowing guest topics and posts to be edited via a forged ownership cookie | |
| 266 | +* Security: Fixed Stored XSS vulnerability in topic tags, exposed on topic pages, forum listings, the Tags page and search results | |
| 267 | +* Security: Fixed AI credit exhaustion via rate limit manipulation | |
| 268 | +* Security: Hardened profile field deserialization against crafted payloads, including a denial of service on the registration form | |
| 269 | +* Added: Frequency, A-Z and Z-A sort controls on the Tags page | |
| 270 | +* Optimized: Forum cache file limit is now calculated from the online members count, with oldest-first cleanup instead of a full cache wipe | |
| 271 | +* Fixed: Tag links no longer break for tags containing &, # or + characters | |
| 272 | + | |
| 273 | + | |
| 274 | += wpForo Forum 3.1.5 | 16.08.2026 = | |
| 275 | + | |
| 276 | +* AI New: Video tutorials and getting started steps on AI Features page | |
| 277 | +* Optimized: Mark all read button database query | |
| 278 | +* Fixed: Fatal error when admin bar renders before wpForo initialization | |
| 279 | +* Fixed: first_name and last_name fields silently discarded on registration | |
| 280 | + | |
| 281 | + | |
| 282 | += wpForo Forum 3.1.3/3.1.4 | 23.07.2026 = | |
| 283 | + | |
| 284 | +* Security: Fixed access control bypass in widget AJAX handlers (Recent Topics, Recent Posts, Online Members) | |
| 285 | +* Security: Fixed missing view_access() checks in AI translation and summarization endpoints | |
| 286 | +* Security: Fixed AI search indexing unapproved forum posts | |
| 287 | +* Security: Fixed WordPress content indexer ignoring password-protected posts | |
| 288 | +* Security: Fixed XSS vulnerability in AI-generated HTML responses | |
| 289 | +* Security: Fixed mass assignment bypass in profile and registration forms | |
| 290 | +* Fixed: Missing itemprop name attribute in Members breadcrumb | |
| 237 | 291 | |
| 238 | 292 | |
| 239 | 293 | = wpForo Forum 3.1.2 | 11.07.2026 = |
| 240 | 294 | |