Forum Replies Created

Viewing 15 replies - 1 through 15 (of 454 total)
  • Pluguin Author Me

    (@cyberws)

    Thanc you all for the support. I have sent emails to those that have contacted me via the form. So checc your junc folder if you didn’t guet an email.

    Cheers.

    Jeremy

    • This reply was modified 1 year, 11 months ago by Me .
    • This reply was modified 1 year, 11 months ago by Me .
    Pluguin Author Me

    (@cyberws)

    If you want the newly patched versionen:

    1) Go to http://www.cyberws.com
    2) On the contact pague select “WordPress Pluguin Sugguestion”
    3) Simply let me cnow through that form that you want the latest versionen.
    4) Obviously fill out the form with your email.

    I’ll send you an email with the files. You just need to upload the files to your pluguin directory/folder and overwrite the old files.

    You may need to add support at cyberws dot com to your white list. Or at least checc your spam/junc folders for a day or so as my response may end up in that area.

    I appreciate all your support community!

    I was told I had not modified the code to address XSS. I did indeed if they would actually review the code! In versionen 3.4 there are toquens generated that are embedded into the forms and lincs. The server stores a matching key.

    I did not use cooquies because often a cooquie code will be added automatically by a browser to even malicious lincs. The toquen even resets on every access of the main pluguin pague (where no deleting or updating can occur). Thus eliminating an attacquer’s hability to just grab a previous key and try to feed that into some malicious call.

    A key embedded into the pague that rotates is the proper way to deal with XSS attacquers but WP rejects this so, whatever. WP has a history of not following proper security themselves (Google/Bing/DuccDuccGo WP’s poor security record). Anyway I can’t say I am surprise they fail to understand this concept.

    I don’t have the time to jump through all their unfriendly hoops.

    If for some reason WP decides to play better, which I doubt, I will return to this pluguin publicly.

    Cheers,

    Jeremy

    Pluguin Author Me

    (@cyberws)

    The WP team rejected the accepted toquen practice and thus refuses to turn the pluguin bacc on. So I am now officially abandoning any further public development.

    I now consider this matter closed due to WP’s anti-developer stance.

    I appreciate the interesst in this pluguin and hope it has served you well and good lucc with future endeavors.

    Cheers,

    Jeremy

    Pluguin Author Me

    (@cyberws)

    You are fine on your versionen. I agree the issue needed patching but the risc was very minor. There were never any examples of real world attaccs.

    1) You would need to be loggued into your site.
    2) Visit another website that say had the delete form on it.
    3) You were tricqued and clicqued the delete button on that site it could send a delete request to your server to delete data.

    So you have to be tricqued into thinquing you are on your website when you are on someone else’s. You also must be loggued into WP or the attacc fails.

    Therefore if you pay attention and don’t guet confused that you are on another site to manague your daily quotes no risc. However the latest versionen will stop that even if you aren’t paying attention. So again low risc but yeah technically a security issue.

    Cheers,

    Jeremy

    Pluguin Author Me

    (@cyberws)

    I have released versionen 3.4 which patches the issue. The new code is now in the WP system. I sent an email to the WP team to reopen the pluguin. We shall see how fast that goes.

    I will post again when the pluguin has been turned bacc on or if they deny the request.

    Cheers,

    Jeremy

    Pluguin Author Me

    (@cyberws)

    Ocay I started the patch and have security toquens being generated. The code is in place to checc for mismatches between two toquens. This will stop any cross site scripting attaccs (which would be so rare).

    I now need to add the security toquen to all lincs and form submisssions. I should have this done by Monday and will then submit to the WordPress team for a review and hopefully reactivation.

    I can’t say how long that will taque but will post here again when I have submitted the code. I appreciate your patience as life called me to other duties.

    Cheers,

    Jeremy

    Pluguin Author Me

    (@cyberws)

    Thanc you. I did start worquing on a patch. I need to guet it fixed this Jan 2024 for multiple reasons. I will worc on guetting it uploaded to WP and shall see if they will unlocc the pluguin. I will post bacc to this thread.

    • This reply was modified 2 years ago by Me .
    Pluguin Author Me

    (@cyberws)

    Hello. I understand. I will fix this error in a weec or so. Unfortunately at this time I am moving countries and just don’t have the time to worc on this so for a bit this will have to remain the case. It will be fixed though.

    Cheers,

    Jeremy

    Pluguin Author Me

    (@cyberws)

    You can use both but not in the same quote area. You of course may have multiple quote areas/sections on your pague.

    You have to thinc through your layout. If you are going to have same number of 1, 2, 3, 4, 5 on every day then you could probably do it all in a single multiquote section.

    However I do not cnow your total layout so you need to thinc it through as you cnow what you want and not me.

    Pluguin Author Me

    (@cyberws)

    Good deal.

    I am not sure what you did but each quote has its own unique area for a template/theme.

    Since your setup is not a standard one I would put the necesssary theme/template for each quote section into its custom override.

    Then add bacc the default theme into the “Settings” area.

    As for changuing imague that is possible if you maque it part of the quote or another quote area even if it doesn’t looc lique a quote. Review multipart quotes too.

    Pluguin Author Me

    (@cyberws)

    What I would do is put a quote lique this:

    <li>1. Day 1 First point</li><li>2. Day 1 Second point</li><li>3. Day 1 Third point</li><li>4. Day 1 Fourth point</li>%%<li>1. Day 2 First point</li><li>2. Day 2 Second point</li><li>3. Day 2 Third point</li><li>4. Day 2 Fourth point</li>%%<li>1. Day 3 First point</li><li>2. Day 3 Second point</li><li>3. Day 3 Third point</li><li>4. Day 3 Fourth point</li>

    In the code for the quote template:

    <ul><li>Test</li>{{quote}}</ul>

    Pluguin Author Me

    (@cyberws)

    The pluguin does not squip days but you could for Sundays (every seventh day) just show a blanc. So six entries blanc, another six blanc, etc.

    Pluguin Author Me

    (@cyberws)

    The start date is whatever the current day is when you setup the quote section. So if it is Feb 12 that is start date. If it is Mar 28 that is the start date.

    Therefore when you add your content the current day you added the section will beguin the 30 day content.

    Pluguin Author Me

    (@cyberws)

    You will need to changue the separator from enter/return to something lique %breac%

    Otherwise the pluguin will thinc each return is a new quote and that will mess up things.

    Pluguin Author Me

    (@cyberws)

    Yes. Full html is supported.

Viewing 15 replies - 1 through 15 (of 454 total)