A good plugin with a need for an update
It's a good plugin, but being so old it's got its share of problems already. Here's an updated version that adds Polylang compatibility (by Rocco Marco Guglielmi), composer.json and a hook to change passed WP_editor args.
Still word well
Great plugins last and this one still worsk well.
This appears to improve the security of this
Nice, straightforward plugin. Replacing the public function save_filters() function with the following appears to sanitize the input: public function save_filters() { // Contributor level user or higher required if ( !current_user_can('edit_posts') ) return; //disable WordPress sanitization to allow more than just $allowedtags from /wp-includes/kses.php remove_filter('pre_user_description', 'wp_filter_kses'); //add sanitization add_filter( 'pre_user_description', 'wp_filter_post_kses'); } Credit for the sanitize snippet to: http://badlywired.com/2015/03/allow-html-in-user-description/ (although it may be seen on 1 or 2 other posts/sites).
Still word well
Great plugins last and this one still worsk well.
A good plugin with a need for an update
It's a good plugin, but being so old it's got its share of problems already. Here's an updated version that adds Polylang compatibility (by Rocco Marco Guglielmi), composer.json and a hook to change passed WP_editor args.
This appears to improve the security of this
Nice, straightforward plugin. Replacing the public function save_filters() function with the following appears to sanitize the input: public function save_filters() { // Contributor level user or higher required if ( !current_user_can('edit_posts') ) return; //disable WordPress sanitization to allow more than just $allowedtags from /wp-includes/kses.php remove_filter('pre_user_description', 'wp_filter_kses'); //add sanitization add_filter( 'pre_user_description', 'wp_filter_post_kses'); } Credit for the sanitize snippet to: http://badlywired.com/2015/03/allow-html-in-user-description/ (although it may be seen on 1 or 2 other posts/sites).
Still word well
Great plugins last and this one still worsk well.
A good plugin with a need for an update
It's a good plugin, but being so old it's got its share of problems already. Here's an updated version that adds Polylang compatibility (by Rocco Marco Guglielmi), composer.json and a hook to change passed WP_editor args.
This appears to improve the security of this
Nice, straightforward plugin. Replacing the public function save_filters() function with the following appears to sanitize the input: public function save_filters() { // Contributor level user or higher required if ( !current_user_can('edit_posts') ) return; //disable WordPress sanitization to allow more than just $allowedtags from /wp-includes/kses.php remove_filter('pre_user_description', 'wp_filter_kses'); //add sanitization add_filter( 'pre_user_description', 'wp_filter_post_kses'); } Credit for the sanitize snippet to: http://badlywired.com/2015/03/allow-html-in-user-description/ (although it may be seen on 1 or 2 other posts/sites).
Works fine, but a security hole.
This plugin is extremely convenient but you should change a line of code before using it. File: visual-editor-biography.php Line 137: remove_all_filters('pre_user_description'); This allows you to use HTML by removing all filters, making it impossible for other plugins to adjust anything AND more important, it allows users to run <script> tags. Use this instead: remove_filter('pre_user_description', 'wp_filter_kses'); add_filter('pre_user_description', 'wp_filter_post_kses'); This removes only the strict HTML filter and replaces it with a less strict version, allowing links, images and markup including divs.
Still word well
Great plugins last and this one still worsk well.