By default, WordPress is automatically updated when a security release is commited.
All my sites are already patched.
Probably yours also. 😉
If you’re a network user, sub sites ARE NOT automatically updated, so you have to check this manually. Normally this is mentionned on your network dashboard.
@danbp hey dan their seems to also be a very big risk with the wordpress commenting system that i have come across from various wordpress expert groups on fb today, and i believe that wordpress are refusing communication on this matter, please take a look at these 2 links, this could affect anyone using the commenting system with buddypress installs too.
when i go to view a profile or anything that has to do with buddy press. this appears:
<b>Warning</b>: strstr(): Empty needle in <b>/home3/filmfilm/public_html/wp-content/plugins/buddypress/bp-core/bp-core-filters.php</b> on line <b>641</b>
this appears as the name of my tab. as the <title> when i go to view source. what does this mean and how do i get rid of it?
i am not an expert with HTML so i would need alot of details and explanation of this issue.
WordPress use Gravatar like BuddyPress.
When BP is activated, it let’s you manage your avatar from the profile.
WP is using get_avatar and BP substitute it with his own code for internal purpose.
Bp-avatar-suggestion let the site admin add an avatar bunch of pictures where users can choose from instead of uploading their own image. And yes, all avatars (wp/bp) are concerned, even if in fact it is the same thing.
FYI the ‘white figure on grey background’ is called Mystery Man in WP jargon. 😉
Also, Gravatar is an external service and on some config, this can slow down a site. Nothing new, it’s the case for any external service (js, font, cloud, social share, etc)
By using the define, you deactivate the call to external gravatar service, and BP fires a local copy of the mystery man. Deactivating Gravatar will also deprive the people who use the service to get their usual picture on your site. It’s not an innocent decision.
Be aware also that the empty option (in wp default avatar setting) is a blank image (and not an empty space), which is also fired by Gravatar.
Can I use WP plugin Countries (Import and manage a list of countries into WordPress site as Custom Post Types) for BP drop down box in Profile fields and how?
Thanks @henrywright! I’ll stick with add_filter('bp_core_fetch_avatar_no_grav', '__return_true'); then if it’s all I need to stop the Buddypress calls. What is it that WordPress calls for? Are you referring to the default ‘white figure on grey background’? Or does WordPress also check for a Gravatar in similar way to Buddypress. (I don’t currently use Gravatar).
Hi @djsteveb , I came across some of those posts you listed which is actually what got me thinking about it in the first place :). I’m trying to be as transparent as possible on user privacy/data on the site I’m creating. Searched the forums a little further and some of the threads are v old so thought I’d check if the stuff there was still applicable or had been deprecated.
Hi @danbp, thanks for the plugin suggestions. I’ve come across a few Buddydev plugins and will probably use their ‘bp-activity-comment-notifier’ plugin since they aren’t part of Buddypress default currently. Trying to keep plugins to a minimum early on.
With regards to the ‘bp-avatar-suggestions’ plugin (which you appear to have inspired), does that override any WordPress calls Henry mentioned above since you are using your own locally stored images? (similar I guess to the new user Twitter eggs)?
hi all i dont know how widespread this is and if it effects anything buddypress related, if this has been posted in the last week or so i apologize as i havent been around, this was just brought to my attention via an email from code canyone where i have a few premium plugins
THE BELOW ARTICLE WAS PUBLISHED ON THE 20TH OF APRIL AT SECURITY ADVISOR
Multiple WordPress Plugins are vulnerable to Cross-site Scripting (XSS) due to the misuse of the add_query_arg() and remove_query_arg() functions. These are popular functions used by developers to modify and add query strings to URLs within WordPress.
The official WordPress Official Documentation (Codex) for these functions was not very clear and misled many plugin developers to use them in an insecure way. The developers assumed that these functions would escape the user input for them, when it does not. This simple detail, caused many of the most popular plugins to be vulnerable to XSS.
To date, this is the list of affected plugins:
Jetpack
WordPress SEO
Google Analytics by Yoast
All In one SEO
Gravity Forms
Multiple Plugins from Easy Digital Downloads
UpdraftPlus
WP-E-Commerce
WPTouch
Download Monitor
Related Posts for WordPress
My Calendar
P3 Profiler
Give
Multiple iThemes products including Builder and Exchange
Broken-Link-Checker
Ninja Forms
I have no trash, the only pages I actually have on the site that are WordPress are related to the blog, there are just 7 pages in total on the whole site 🙂 I believe in minimalism.
I’ve just tried it on twenty thirteen (the latest update yesterday) and the groups work perfectly, even for my test user who is a forum participant and contributor for WordPress AND member of two hidden groups. I had tested it previously, but it did’t work on the previous version of the theme. I didn’t even have to deactivate any plugins.
I then tested it with all the themes from 2011-2015 and they all work too.
So… It looks like I need to take this back to my theme developers… Can you please give me so info that I can relay to them so they can get the hidden groups displaying correctly? Or, is it possible to copy the appropriate BuddyyPress files from one of the WordPress themes and put it somewhere in the child theme of the theme I am using? If so… Which ones and where would I find them?
The theme I am using integrates BuddyPress in it, but not in any great detail.
Thank you very much. And what about the Chinese language
In wordpress has Chinese. And in the Chinese language does not have buddypress.
Where to write translations? I want to translate their own.
I added Chinese language on the site
I have tried with multiple themes, including the 2015, 14 and 13. I am currently using Firmasite (which works but isn’t the most user-friendly in other ways). I have BBpress, Buddypress, Mailchimp for WordPress, Akismet (activated), Buddypress Group Chat, Buddypress Security Check, Jetpack. I try and keep the plugins to a minimum as my WordPress site is only used for the forums – I use efiction in a subfolder for the main part of my site.
this is really a wordpress/xampp setup issue not a buddypress thing. i can’t really help you because i never had any trouble setting mine up and i use mac anyway but you might be able to get more eyeballs on your problem by using the support resources for wordpress and/or xampp since buddypress is a sort of baby universe compared to the larger wordpress universe which contains it there are far fewer people here then there are there.
Great to see you’re interested in developing BuddyPress themes. It might be worth also asking your question over at wordpress.org; I’m hoping there’ll be some WordPress theme authors who’ll want to turn their hand to themes for BuddyPress.
Author
Search Results
Viewing 25 results - 8,576 through 8,600 (of 32,678 total)