BuddyPress 2.7.4 Patches Security Vulnerability That Could Allow Arbitrary File Deletion

The BuddyPress development team has released BuddyPress 2.7.4 to address a security vulnerability that affects all versions back to 2.0. According to John James Jacoby, lead developer of BuddyPress, “This version patches a vulnerability to the BuddyPress core attachments API that could allow arbitrary file deletion on certain installation configurations.” The vulnerability was responsibly disclosed by Sam Pizzey through the HackerOne …

WordPress.org Launches Homepage Redesign

WordPress.org made its new homepage redesign live today. The meta team worked quickly to put the new design in place in time for the holidays. “While this is only the first iteration, the plan is to continue design and development to create something truly amazing,” Mark Uraine said in the announcement. “This is the first step toward that goal.” The …

WP-CLI Project Launches Patron Support Model to Fund Ongoing Development

WP-CLI contributors have been working towards a more sustainable future for the project throughout 2016. Daniel Bachhuber, the project’s official maintainer, has launched an experiment to fund ongoing maintenance and new development, asking potential patrons, “How much is WP-CLI worth to you?” Options for contributions range from $100/yr – $7500/yr. This particular funding experiment is not asking for one-time contributions …

Matt Mullenweg Proposes WordPress Growth Council

During the last WordSesh event held in August 2016, Matt Mullenweg joined the community for a session where he spoke about the growth of WordPress and his thoughts on confronting the project’s external threats. Mullenweg floated the idea of a WordPress Growth Council – a collection of individuals and organizations interested in contributing to WordPress’ growth. “We have very direct …