extension icon indicating copy to clipboard operation
extension copied to clipboard

Prevent injection of code snippets into WordPress inputs

Open Cactii1 opened this issue 2 years ago • 8 comments

No idea why but this wallet extension injects its code into many different editing fields when editing a Wordpress web site with the plugin enabled.

Cactii1 avatar Aug 07 '22 19:08 Cactii1

This shouldn't happen. Mind providing a screenshot of what you see so we can diagnose the problem?

markmhendrickson avatar Aug 07 '22 19:08 markmhendrickson

It only happens when editing with the visual editor. Hiro-Visual Hiro-Text

Cactii1 avatar Aug 07 '22 19:08 Cactii1

Obviously I cannot replicate it when the plugin is disabled in my browser.

With Wordpress there are two editing modes (you can see a visual and a text tab on the main editing field) and it seems to only happen when the visual editing tab is selected.

There are other fields on this editing page that are also effected and have this same code injected into the editing field.

Cactii1 avatar Aug 07 '22 19:08 Cactii1

Thanks for the screenshot and extra context! We'll investigate.

markmhendrickson avatar Aug 08 '22 08:08 markmhendrickson

Hmm, this is likely owing to the addition of all_frames. Surprised it injects into a wysiwyg though.

While we fix, you can use this option to disable the extension by domain image

kyranjamie avatar Aug 08 '22 08:08 kyranjamie

Another report image

314159265359879 avatar Mar 23 '23 11:03 314159265359879

I picked this issue up again to try and get it closed off but I'm now unable to re-produce it on Firefox.

I setup a fresh installation of Wordpress and installed Classic Editor and I cannot reproduce it using Hiro Waller V 6.3.1 and FF 116.0.2 (64-bit) on MAC.

It's tricky to stress test it due to https://github.com/hirosystems/wallet/issues/4030 so we could re-visit once that is solved.

Originally I could reproduce the issue right away but then on subsequent attempts I was unable to.

pete-watters avatar Aug 14 '23 09:08 pete-watters

I noticed this poor review we have on the Chrome store about this issue. We should probably try and get this fixed soon

Screenshot 2024-02-01 at 17 14 22

pete-watters avatar Feb 01 '24 17:02 pete-watters