Comment Form CSRF Protection

0

WordPress has an 9 year old unfixed security vulnerability that it does not properly validate incoming comments. An attacker can trick both anonymous and logged in users to post comment

Version
Last updated
Active installations
WordPress Version
Tested up to
PHP Version
Rating
Total ratings
Tag
This plugin is outdated and might not be supported anymore.

Description

WordPress has an 9 year old unfixed security vulnerability that it does not properly validate incoming comments.

An attacker can trick both anonymous and logged in users to post comments on a victim site without them realizing, while using their own credentials.

See this issue for more information: https://core.trac.wordpress.org/ticket/10931

This is a tiny (fewer than 40 effect lines of code) module that adds a secure token to the comment form and validate it before accepting any comment, thus making your comment forms secure as they should’ve been for all these years!

It provides no UI – just install it and you are all set!

  1. This plugins adds a secret cryptographically-secure token to the comment form. This is a unique value and is computationally impractical to guess it.
  2. Upon comment subission, the comment is rejected if the secret tokens are not present or computationally invalid.