plugin-icon

Comment Form CSRF Protection

제작자: Ayesh Karunaratne·
Prevent Cross-Site Request Forgery attacks on your comments form.
평가
5
버전
1.4
활성화된 설치 항목
500
최근 업데이트일
Jul 23, 2023
Comment Form CSRF Protection

WordPress has a 12-year-old unfixed security vulnerability that it does not properly validate incoming comments.

An attacker can trick both anonymous and logged-in users to post comments on a victim site without them realizing, while using their own credentials.

See this issue for more information: https://core.trac.wordpress.org/ticket/10931

This is a tiny (fewer than 40 effect lines of code) module that adds a secure token to the comment form and validate it before accepting any comment, thus making your comment forms secure as they should\’ve been for all these years!

It provides no UI – just install it, and you are all set!

  1. This plugin adds a secret cryptographically-secure token to the comment form. This is a unique value and is computationally impractical to guess it.
  2. Upon comment submission, the comment is rejected if the secret tokens are not present or computationally invalid.
무료Business 요금제에서
설치하면 WordPress.com 서비스 약관서드파티 플러그인 약관에 동의하게 됩니다.
테스트된 버전
WordPress 6.3.7
이 플러그인은 다운로드할 수 있으며 에서 사용할 수 있습니다.