PluginProbe
wpForo Forum / 3.2.0
wpForo Forum v3.2.0
3.2.0 3.1.7 3.1.6 3.1.5 3.1.4 3.1.2 3.1.1 3.1.0 3.0.9 3.0.8 3.0.7 trunk 1.0.0 1.0.1 1.0.2 1.1.0 1.1.1 1.1.2 1.2.0 1.3.0 1.3.1 1.4.0 1.4.1 1.4.10 1.4.11 All 140 releases
← All changes | readme.txt +57 -3 3.1.2 → 3.2.0 View file →
@@ -1,10 +1,10 @@
1 1 === wpForo Forum ===
2 2 Contributors: gVectors Team
3 3 Tags: forum, forums, forum plugin, bbpress, community
4 4 Requires at least: 5.2
5 -Tested up to: 7.0
6 -Stable tag: 3.1.2
5 +Tested up to: 7.1
6 +Stable tag: 3.2.0
7 7 Requires PHP: 7.1
8 8 License: GPLv2 or later
9 9 License URI: https://www.gnu.org/licenses/gpl-2.0.html
10 10
@@ -135,9 +135,21 @@
135 135
136 136 [Terms of Service](https://gvectors.com/terms-and-conditions/)
137 137 [Privacy Policy](https://gvectors.com/privacy-policy/)
138 138
139 +**gVectors Addons News & License Reminders** (store.gvectors.com)
139 140
141 +If the forum administrator explicitly enables the addon news service (it is disabled by default and requires opt-in), wpForo connects to store.gvectors.com once per day to:
142 +
143 +* Fetch news about new addons, new features and announcements (endpoint: /news) — this request sends no site-specific data beyond standard HTTP request information
144 +* Check for addon licenses that are close to expiration (endpoint: /at-risk-licenses) — this request sends your site address, an anonymous site identifier (an HMAC hash generated from your site domain and your WordPress security salts), and the slugs and installed versions of your gVectors addons
145 +
146 +No personal data, no email addresses, and no forum content is ever sent to this service. News notifications are shown as dismissible messages in the WordPress admin, and summary emails are sent by your own site (via your own mail server) to site administrators. The service can be disabled at any time from the wpForo Addons page, which stops all outbound requests immediately.
147 +
148 +[Terms of Service](https://gvectors.com/terms-and-conditions/)
149 +[Privacy Policy](https://gvectors.com/privacy-policy/)
150 +
151 +
140 152 == Installation ==
141 153
142 154 1. Install wpForo Forum plugin in Dashboard > Plugins admin page. Then activate it.
143 155 2. If you have more than 100 users wpForo forum plugin prompts you synchronize users.
@@ -231,10 +243,52 @@
231 243
232 244 - After the update, please delete all caches and purge CDN if you have
233 245 - After the update, please flush Redis Object Cache if you have this cache enabled
234 246
235 -[wpForo Forum v3.0 Release Summary](https://wpforo.com/community/wpforo-announcements/wpforo-3-0-is-released/)
247 +[wpForo Forum v3.2 Release Summary](https://wpforo.com/community/wpforo-announcements/wpforo-3-2-is-released/)
236 248
249 +
250 +
251 += wpForo Forum 3.2.0 | 25.09.2026 =
252 +
253 +* Addons Store: Purchase and manage addon licenses directly in your WordPress dashboard. No need to go to gVectors Store, purchase, then download and install. Now you can do one-click purchase, install, and update addons directly in your wpForo > Addons admin page.
254 +
255 +
256 += wpForo Forum 3.1.7 | 22.09.2026 =
257 +
258 +* Security: Fixed Stored XSS vulnerability in some text fields
259 +* Fixed: Infinite recursion causing fatal error and 504/508 timeouts on forum pages
260 +
261 += wpForo Forum 3.1.6 | 18.09.2026 =
262 +
263 +* Compatibility: WordPress 7.1
264 +* Security: Fixed PHP Object Injection vulnerability in custom form fields
265 +* Security: Fixed Guest Post Takeover vulnerability allowing guest topics and posts to be edited via a forged ownership cookie
266 +* Security: Fixed Stored XSS vulnerability in topic tags, exposed on topic pages, forum listings, the Tags page and search results
267 +* Security: Fixed AI credit exhaustion via rate limit manipulation
268 +* Security: Hardened profile field deserialization against crafted payloads, including a denial of service on the registration form
269 +* Added: Frequency, A-Z and Z-A sort controls on the Tags page
270 +* Optimized: Forum cache file limit is now calculated from the online members count, with oldest-first cleanup instead of a full cache wipe
271 +* Fixed: Tag links no longer break for tags containing &, # or + characters
272 +
273 +
274 += wpForo Forum 3.1.5 | 16.08.2026 =
275 +
276 +* AI New: Video tutorials and getting started steps on AI Features page
277 +* Optimized: Mark all read button database query
278 +* Fixed: Fatal error when admin bar renders before wpForo initialization
279 +* Fixed: first_name and last_name fields silently discarded on registration
280 +
281 +
282 += wpForo Forum 3.1.3/3.1.4 | 23.07.2026 =
283 +
284 +* Security: Fixed access control bypass in widget AJAX handlers (Recent Topics, Recent Posts, Online Members)
285 +* Security: Fixed missing view_access() checks in AI translation and summarization endpoints
286 +* Security: Fixed AI search indexing unapproved forum posts
287 +* Security: Fixed WordPress content indexer ignoring password-protected posts
288 +* Security: Fixed XSS vulnerability in AI-generated HTML responses
289 +* Security: Fixed mass assignment bypass in profile and registration forms
290 +* Fixed: Missing itemprop name attribute in Members breadcrumb
237 291
238 292
239 293 = wpForo Forum 3.1.2 | 11.07.2026 =
240 294