這個外掛並未在最新的 3 個 WordPress 主要版本上進行測試。開發者可能不再對這個外掛進行維護或提供技術支援,並可能會與更新版本的 WordPress 產生使用上的相容性問題。

Comment Form CSRF Protection

外掛說明

WordPress has a 12-year-old unfixed security vulnerability that it does not properly validate incoming comments.

An attacker can trick both anonymous and logged-in users to post comments on a victim site without them realizing, while using their own credentials.

See this issue for more information: https://core.trac.wordpress.org/ticket/10931

This is a tiny (fewer than 40 effect lines of code) module that adds a secure token to the comment form and validate it before accepting any comment, thus making your comment forms secure as they should\’ve been for all these years!

It provides no UI – just install it, and you are all set!

  1. This plugin adds a secret cryptographically-secure token to the comment form. This is a unique value and is computationally impractical to guess it.
  2. Upon comment submission, the comment is rejected if the secret tokens are not present or computationally invalid.

螢幕擷圖

安裝方式

  1. Upload the plugin files to the /wp-content/plugins/ directory, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress.
  3. You are all set! There is nothing to configure. Your comment forms will contain the hidden token fields that will be properly validated upon submission.

使用者評論

2021 年 6 月 23 日
I have inspected the plugin source. A great idea was implemented. thanks for the awesome plugin. it helps to fix the CSRF Tokens issue. Can you please tell me how to implement the same for search box and contact form 7 to fix the CSRF issue? Is there any hook is available? Thanks, Saravanan
2019 年 10 月 23 日
Our website was “hacked” as part of the Bug Bounty program. We closed the gap with the help of this plugin. Many thanks to the developer! Unbelievable that WordPress has not closed this gap within the last 10 years!
閱讀全部 2 則使用者評論

參與者及開發者

以下人員參與了開源軟體〈Comment Form CSRF Protection〉的開發相關工作。

參與者

將〈Comment Form CSRF Protection〉外掛本地化為台灣繁體中文版

對開發相關資訊感興趣?

任何人均可瀏覽程式碼、查看 SVN 存放庫,或透過 RSS 訂閱開發記錄

變更記錄

1.0

  • Initial release.

1.1

This is a minor release that contains minimal changes.

  • Marks the plugin as tested up-to WordPress 5.3
  • Fix in composer.json file that it required PHP^7.2 instead of intended ^7.1
  • A micro optimization in the plugin to call the lambda function directly within the CSRF check.

1.4

Minor release that contains several typo fixes and WordPress 6.3 compatibility