BuddyPress 2.7.4 Patches Security Vulnerability That Could Allow Arbitrary File Deletion

The BuddyPress development team has released BuddyPress 2.7.4 to address a security vulnerability that affects all versions back to 2.0. According to John James Jacoby, lead developer of BuddyPress, “This version patches a vulnerability to the BuddyPress core attachments API that could allow arbitrary file deletion on certain installation configurations.” The vulnerability was responsibly disclosed by Sam Pizzey through the HackerOne …

WordPress.org Launches Homepage Redesign

WordPress.org made its new homepage redesign live today. The meta team worked quickly to put the new design in place in time for the holidays. “While this is only the first iteration, the plan is to continue design and development to create something truly amazing,” Mark Uraine said in the announcement. “This is the first step toward that goal.” The …