[wp-trac] [WordPress Trac] #41210: Don't show preview of links in spammed or trashed comments
WordPress Trac
noreply at wordpress.org
Fri Jun 30 09:32:03 UTC 2017
#41210: Don't show preview of links in spammed or trashed comments
--------------------------+-----------------------------
Reporter: tobifjellner | Owner:
Type: enhancement | Status: new
Priority: normal | Milestone: Awaiting Review
Component: Comments | Version:
Severity: normal | Keywords:
Focuses: |
--------------------------+-----------------------------
In the wp-admin moderating view, when you hover over links in comments, a
preview of the linked page is automatically generated and shown.
For normal comments, this is a nice feture.
But in the case of spam comments or evil comments I'm quite concerned
about this, since these previews at some point might create some risk for
drive-by infections, and as a minimum, may allow such comments to "phone
home" and obtain my personal ip-address, should I happen to hover over any
link.
And it's quite easy to hover over a link even by mistake, I try to make
sure that my cursor is located on a different part of the screen before
loading pages with spam comments.
Suggestion:
Don't include code for automatic preview of links in the folders spam and
trash.
Somewhat related: #31299
--
Ticket URL: <https://core.trac.wordpress.org/ticket/41210>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform
More information about the wp-trac
mailing list