dlx
(@deeluuxe)
It would be good knowing the reason of the security issues.
Does anyone have some information about this?
I’ve rasied a ticket on BuddyPress Trac asking to integrate this plugins features into BP core.
BP is working on GDPR exports, I would think that these will include all profile field data, so would include this plugins features.
Hello, we forked the plugin, fixed any issues and it is available here for free and it is backward compatible https://ww.wp.xz.cn/plugins/bp-xprofile-custom-fields/
@deeluuxe
Since you asked, The problem was any user could delete other user’s file(or any file/image in wp-content).
To all following this topic,
We had rewritten this plugin too(It’s more of a complete rewrite than a fork) and cleaned up various issues with the plugin(settings, output and manageable code).
You may use the plugin from here
https://ww.wp.xz.cn/plugins/bp-xprofile-custom-field-types/
Also, GDPR support is coming to BuddyPress core. You may want to follow the tickets by Boone here
https://buddypress.trac.ww.wp.xz.cn/ticket/7698#comment:11