Database info stored as PHP constant, potential security risk
-
Any admin user could var_dump them in a theme template file…isnt this be a potential security?
It makes sense that the initial admin user account that setup the WP install can have access to these constants, being that they entered this information into the installer…but any other admin user account (that is not uid #1) doesn’t need really need access to these.
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘Database info stored as PHP constant, potential security risk’ is closed to new replies.