Bug / URL guessing
-
Hello WP Maintenance team,
we just noted a problem with URL guessing made by WordPress and your plugin.
When your plugin is active and shows the maintenance screen to users that are not logged in, one does this to avoid anything of the website’s content to be revealed to the outside.
But it seems that you forgot to block WordPress’ URL guessing. We have a website with active maintenance plugin and when we enter an URL into the browser like
https://WWW.DOMAIN.TLD/w
(just with a “w” in the end), then the browser URL switches to the URL
https://WWW.DOMAIN.TLD/submenu/"some-word-with-a-leading-w"
This is WordPress’ URL guessing that rewrites the URL. But if one has your plugin active he might not want even this information to be revealed to the outside. Maintenance is maintenance. Then no URL path should be revealed.
Are we wrong?
Many greetings,
-doffine
- The topic ‘Bug / URL guessing’ is closed to new replies.