=== Subscribe to Comments ===
Tags: comments, subscription, email
Contributors: markjaquith, joen
Requires at least: 6.2
Requires PHP: 7.4
Tested up to: 7.1
License: GPLv2 or later
Stable tag: 2.3.3

Subscribe to Comments allows commenters on an entry to subscribe to e-mail notifications for subsequent comments.

== Description ==

Subscribe to Comments is a robust plugin that enables commenters to sign up for e-mail notification of subsequent entries.  The plugin includes a full-featured subscription manager that your commenters can use to unsubscribe to certain posts, block all notifications, or even change their notification e-mail address!

== Installation ==

1. Put subscribe-to-comments.php into [wordpress_dir]/wp-content/plugins/
2. Go into the WordPress admin interface and activate the plugin
3. Optional: if your WordPress theme doesn't have the comment_form hook, or if you would like to manually determine where in your comments form the subscribe checkbox appears, enter this where you would like it: `<?php show_subscription_checkbox(); ?>`
4. Optional: If you would like to enable users to subscribe to comments without having to first leave a comment, place this somewhere in your template, but make sure it is **outside the comments form**.  A good place would be right after the ending `</form>` tag for the comments form: `<?php show_manual_subscription_form(); ?>`

== Frequently Asked Questions ==

= How can I tell if it's working? =

1. Log out of WordPress
2. Leave a comment on an entry and check the comment subscription box, using an e-mail that is NOT the WP admin e-mail address or the e-mail address of the author of the post.
3. Leave a second comment using a different e-mail address than the one you used in step 2 (it can be a bogus address).
4. This should trigger a notification to the first address you used.

= I'd like the subscription checkbox to be checked by default.  Can I do that? =

Not anymore.  But the checkbox status will be remembered on a per-user basis.

= My subscription checkbox shows up in a strange place.  How do I fix it? =

Try unchecking the CSS "clear" option.  Beyond that, you're on your own with CSS positioning.

== Changelog ==

= 2.3.3 =

* Security: Verify email changes through the destination inbox before transferring subscriptions or revealing its management key. Confirmation links are purpose-bound, expire after one day, and cannot be replayed after use.
* Security: Rotate management keys again to revoke links that could have been exposed by the email-change flow. Retired keys remain recognizable but never authorize access. Subscriptions and existing settings are preserved.
* Security: Protect migration markers with a server-secret signature so old author-accessible settings cannot preserve a known key salt.
* Honor double opt-in for standalone subscriptions and require fresh inbox confirmation for guest subscriptions, including addresses already subscribed elsewhere. Limit confirmation emails to one per address per day.
* Preserve valid percent and apostrophe characters in subscriber email addresses, and make unsubscribe controls work immediately after confirmation.
* Restrict custom layout includes to active-theme PHP files, prevent management-page referrer disclosure, and disable caching of private management pages.
* Do not trust self-edited WordPress profile email addresses as proof of inbox ownership. Non-administrators manage subscriptions through emailed links.
* Pause email-only notifications when posts become private, unpublished, or password-protected. Preserve subscriptions and hide nonpublic post titles from unauthorized management-page viewers.
* Thanks to Het Kalariya for reporting the original vulnerabilities.
* Improve modern PHP compatibility and initialize the plugin after WordPress APIs and translations are available.
* Restore notifications for modern WordPress comment types and fix double opt-in, email-change, and unblock flows.
* Protect subscription-manager and standalone-subscription forms with nonces, including administrator requests.
* Validate malformed form values and disallow standalone subscriptions to unpublished, password-protected, or closed posts.
* Escape frontend and administrator output, restrict form markup, and prepare SQL identifiers and limits.
* Require WordPress 6.2 or later for prepared SQL identifier support, and PHP 7.4 or later. Tested on WordPress 7.1.

= 2.3.2 =

* Security: Stop using unsigned comment-email cookies to identify subscribers or disclose their management keys, and prevent key disclosure when subscribing without commenting.
* Security: Validate and escape subscription-manager return links to prevent reflected cross-site scripting.
* Security: Restrict plugin settings to administrators and sanitize notification sender headers to prevent email header injection.
* Security: Rotate subscription-management keys once on existing installations. Old management and confirmation links are revoked, with an explanatory message and an administrator notice. Existing subscriptions are preserved, and new emails contain fresh links.
* Preserve private key settings when saving plugin options so links remain valid and the security rotation is not repeated.
* Guest subscribers manage subscriptions through emailed links. Subscribing without commenting now shows confirmation on the current page instead of redirecting to the subscription manager.
* Thanks to Het Kalariya for reporting these vulnerabilities.

== Upgrade Notice ==

= 2.3.3 =

Security and compatibility update. Requires WordPress 6.2 and PHP 7.4 or later. Existing subscriptions are preserved; older management links are revoked. Email changes must be confirmed at the new address. Guest subscriptions honor double opt-in when enabled.

= 2.3.2 =

Security update. Existing subscriptions are preserved, but links in older notification and confirmation emails are revoked. Use a link in a new email or contact the site administrator.
