Big security hole
-
Installed plugin and changed wp-login.php to login.
The new login url works just fine. That’s not the problem.
The problem:
I LOG OUT of admin
The login page appears at the correct url
I DON’T log in again
I go to wp-admin.php… and I’m AUTOMATICALLY logged back in to admin!
Rinse and repeat. Same thing.Logging out of admin doesn’t log me out at all because I can get back into admin by simply going to wp-admin.php.
Very bad.
If I disable plugin, log out and try wp-admin.php, I’m asked to log in again, as expected.
WordPress 4.1. Tested with latest versions of Firefox, Internet Explorer, Chrome.
Viewing 8 replies - 1 through 8 (of 8 total)
Viewing 8 replies - 1 through 8 (of 8 total)
- The topic ‘Big security hole’ is closed to new replies.