Kevin MuldoonWordPress Top Commentators Hijack Fix Released

Written by Kevin Muldoon from System0 on April 30, 2008

New BloggingTips author Sarah recently noticed a major flaw in the popular Show Commentators Plugin for WordPress.

As Sarah explained last month :

To briefly explain, the plugin creates the top commentators list by counting the number of comments made per name which is easily forged, by accident or on purpose. It then links the name using the last URL given on that name’s comment. So all you need is someone to forge someone else’s name and use a different URL and they get a nice little, usually no followed, link from your site.

Thankfully, Sarah was able to fix it by creating the top commentators list using email addresses instead of names. As she points out, it is very easy to forge a name which is being displayed compared to a hidden email address which is not.

If you use the top commenators plugin I recommend you downloading this fix so that you no cheaters get on your list.

You can download the fix from the link below :

Top Commentators Hijack Fix

Written by Kevin Muldoon from System0 on April 30, 2008 | Filed Under WordPress Plugins

Share with others

  • StumbleUpon
  • Add to Delicious
  • Mixx

One Response so far | Have Your Say!

  1. David Bradley  |  May 1st, 2008 at 3:23 am #

    David Bradley - Gravatar

    I take it someone has notified the original plugin author so that the patch can be incorporated into the source…

    db

Trackbacks to 'WordPress Top Commentators Hijack Fix Released'

Leave Feedback

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>