Thanks, Rolando, But No…
Saturday, July 5th, 2008One of my top commentators, Rolando, left a comment encouraging me to keep blogging and mentioning how useful he finds my blog.
Except, it wasn’t Rolando.
It was a spammer using Rolando’s name but with a different eMail address and blog URL.
While it went into moderation and did not get posted as a comment, it did change the URL under Top Commentators in my sidebar from Rolando’s site to this spammer’s URL. Even marking it as spam didn’t change that.
The only way to fix it was to completely delete the comment. Then, the sidebar URL reverted back to the real Rolando’s URL.
I’ve mentioned this before, and this serves as a reminder to regularly delete your spam comments, especially if you’re using the Show Top Commentators plugin.
I’d bet the change in version 1.05 (”Change: Changed the logic for retrieving a commentators URL from their most used URL to their last used URL.”) has something to do with it.
Before I eMail the author of the plugin, has anyone else experienced this as well? I’m trying to figure out if it’s an actual issue with the plugin, or if it’s something unique to my blog. If you’re using version 1.05 and are willing to let me post a fake comment on your blog to test this (you can, of course, delete the comment afterwards!), please leave a message in the comments.
If you are using the Top Commentators Widget, this does not seem to be vulnerable to this potential exploit. At least version 0.999 appears to be okay. (Thanks Pete!)
Popularity: 1% [?]

