• Resolved pat1701

    (@pat1701)


    Hello! I developed a website with woocommerce and today I received a complaint from a user who accessed his “my account” page, and saw orders that were not made by him. By clicking “view”, he had access to the other buyer’s personal data. This is really happening on the site and it never happened before. WordPress is updated, as well as woocommerce. How to solve? Thanks a lot!

    The page I need help with: [log in to see the link]

Viewing 11 replies - 1 through 11 (of 11 total)
  • Hello @pat1701,

    That’s a scary situation! Most often this happens when the account page is cached. It could be a caching plugin or caching by the web host.

    Looking at the URL you sent, it looks like the account page has a slug, minha-conta. You’ll want to make sure that slug is excluded from any caching to keep customers from seeing one another’s data. It’s also good to exclude caching on the cart and checkout pages too.

    There’s a support document about configuring caching plugins too:

    https://docs.woocommerce.com/document/configuring-caching-plugins/

    Try disabling that and see if it helps. If you still have trouble, let me know.

    Cheers!

    Thread Starter pat1701

    (@pat1701)

    Hello, @3sonsdevelopment
    Thanks very much for your feedback and willingness to help.

    We have LiteSpeed Cache plugin installed in this site, but it didn’t works. We also tested WP Fastest Cache but it don’t have any result. I don’t understand – until the end of last year we never had this problem – it started this year, even though the site is exactly the same (no plugins were added or turned off).

    I don’t Know what I have to do…

    Hi @pat1701,

    If you still have this trouble with all caching plugins disabled, I would reach out to the web host and see if they have any caching enabled. It’s possible the host could have changed the server configuration.

    If they don’t have any caching, then the next step would be to temporarily disable all plugins except for WooCommerce and switch to the Twenty Nineteen theme. Then see if you still have the problem. If it works correctly now, then that would indicate there is a code conflict.

    You could then switch back to your theme and test again. Then continue testing by activating the plugins one by one and testing as you go. When it stops working, the last one activated is likely causing the trouble.

    Let us know what you find out.

    Hi @pat1701,

    It’s been a while since we heard from you, so I’m marking this thread resolved. Hopefully, you’ve been able to resolve this, but if you haven’t, please let open up a new topic and we’ll be happy to help out.

    Thread Starter pat1701

    (@pat1701)

    Hi, @3sonsdevelopment!
    I didn’t resolved this problem yet!

    I need to wait my client close event’s sales this weekend – Only next week I will be able to keep the site in maintenance mode and do all testing by turning off the plugins!

    Please do not close this post yet!

    Hey @pat1701,

    Sorry about that. I moved it back to unresolved for you. Let us know what you find out next week and we’ll go from there.

    Have a great weekend!

    Hi @pat1701,

    I’m just checking in to see how things went after this sale ended with the conflict testing.

    Let us know what you find out.

    Thanks!

    Thread Starter pat1701

    (@pat1701)

    Hi! I think the problem was the oldest orders make before we instal woocommerce. I moved all orders to trash and it not appears anymore. This problem dont occurred months ago… maybe some plugin’s atualization have make it happening. So, new orders from unknown clients don’t appear in the page “my orders”.

    Hi @pat1701,

    That’s an interesting situation. If orders were added to the site which were placed outside of WooCommerce, then it’s possible they weren’t configured correctly.

    You could use a plugin like User Switching to log in as one of these customers and see what they’re finding in the order section. If there are orders from other customers, you could view the orders and find out for certain if they are old orders.

    If they are old orders, they may need to be edited and assigned to the correct users. If they aren’t old orders, I would suggest taking a look at caching on the site.

    Let us know what you find out.

    Thread Starter pat1701

    (@pat1701)

    Hi, @3sonsdevelopment ! Thanks a lot for your response!

    Yes, they are old orders, but it isn’t in use today. We put it in trash and they did’t appear in page “my orders” anymore. The problem was that we could see orders from another persons, including their documents numbers and their addresses. For now, the problem is solved (old orders in trash)!

    Hey @pat1701,

    I’m glad you were able to get that mystery solved! If you need help in the future, please feel free to open up a new topic and we’ll be happy to assist ??

Viewing 11 replies - 1 through 11 (of 11 total)
  • The topic ‘I Can see order from unknown people im my account’ is closed to new replies.