• Resolved mperry8304

    (@mperry8304)


    I see that this plugin has been removed and is pending review. Does anyone know what’s going on with this. I really like this plugin and am using it on several sites.

Viewing 15 replies - 1 through 15 (of 18 total)
  • Would like to know too #subscribed

    hassan

    (@sangshenas)

    its because of security issue that reported in patchstack and not solved currently..

    @hassan – are you sure? I did not get any notice about this, but instead found this: https://github.com/zedzedzed/table-of-contents-plus/commit/eec367b0e4d732b4fb6a7468aab30421d335087e

    @hassan – ok, see it now – probably e-mail notice has not been delivered

    hassan

    (@sangshenas)

    @dziudek According to the link you sent, the owner of the plugin has abandoned it. Therefore, this security problem will never be solved. With this condition, it seems that this good plugin will be deleted forever?
    I wish WP give its support to someone else.

    Thread Starter mperry8304

    (@mperry8304)

    I’m having problems finding info on the security problem. Where can I find that?

    hassan

    (@sangshenas)

    @mperry8304 here is the link

    Thread Starter mperry8304

    (@mperry8304)

    @sangshenas Thanks so much!

    “This security issue has a low severity impact and is unlikely to be exploited.” I feel like now I have time to figure out my options and/or wait to see if anyone takes the plugin over.

    Bill

    (@billjamshedji)

    I’m also affected by this issue, for the last two weeks Jetpack has been warning me about this plugin but my site really depends upon it. I also saw the “This security issue has a low severity impact and is unlikely to be exploited.” message, which is a bit of a relief.

    As it’s been abandoned I was wondering if any programmer would be interested in taking it over? I’d be happy to throw in a few dollars to have someone update this, and I expect I’m not alone.

    Otherwise, does anyone know of an equivalent plugin that uses the same shortcode (i.e. [toc)? I have eight years worth of content formatted this way, so if I have to replace the plugin I’d like one that doesn’t require me to reformat all those pages.

    hassan

    (@sangshenas)

    @billjamshedji i install “Joli Table Of Contents” plugin and it is very customizable. try it.

    Bill

    (@billjamshedji)

    @sangshenas Thanks! It looks good, it’s current and rated well, but the shortcode is [joli-toc] and not [toc]. Still it might work, there are a few search/replace plugins (or just an SQL query) that might be able to do this. Manually changing almost 500 posts isn’t my idea of fun!

    @billjamshedji It is rather simple to write some glue logic that just registers the shortcode [toc] and does nothing more than calling the other shortcode internally. Please note that this is just a makeshift solution to spare you the work of editing all your posts manually or via search-replace plugin, and not a recommended practice. I’m just pragmatic. ??

    Bill

    (@billjamshedji)

    @oldgrumpyde That’s a great idea, I will test it out on my staging server. Thanks!

    Personally I’m going to migrate to Easy Table of Contents

    It’s a fork of Table of Contents Plus so the settings are very similar. Also it doesn’t add thousands of settings that you probably won’t use but that complicate everything.

    The shortcode is a bit different but with a search/replace you can fix it. The problem may be if you’ve used attributes, since they don’t match.

    Regards.

    • This reply was modified 1 week, 4 days ago by efquintana.
    Plugin Author benjaminprojas

    (@benjaminprojas)

    Hey all! I just wanted to jump in here to let you know that my team and I at AIOSEO have adopted the Table of Contents Plus plugin and we have already submitted a patch for the security vulnerability.

    We have long admired and used this plugin, and once we heard it was abandoned, we have been working hard to adopt and fix the outstanding issues so that you can use it without any ongoing issues. We’re hoping a new version gets posted within the next few days so you can quickly update.

    We’ll be looking to add any missing features and improvements, so if there is anything that you’d like to see added, feel free to reach out and let us know!

Viewing 15 replies - 1 through 15 (of 18 total)
  • You must be logged in to reply to this topic.