• Any URL with ?page=wc-settings&tab=checkout tabs shows the addressfinder settings options. This seems like a bug but also a bit of a security concern.

Viewing 12 replies - 1 through 12 (of 12 total)
  • Thread Starter technicalx

    (@technicalx)

    Problem still exists in Version:?1.5.7

    Thread Starter technicalx

    (@technicalx)

    Will this be looked into? This is in the admin only pages btw.

    • This reply was modified 1 year, 6 months ago by technicalx.
    Thread Starter technicalx

    (@technicalx)

    2 months and no reply on this fairly critical issue?

    Thread Starter technicalx

    (@technicalx)

    I have a test wordpress if you want login to see this happening on a default install, only WooCommerce and Addressfinder plugin is installed and has this major bug.

    You can easily test this in a WordPress sandbox, there’s lots of free ones available.

    this seems like the plugin wants to steal payment api keys because it’s visible on those pages.

    Thread Starter technicalx

    (@technicalx)

    This is still an issue after 3 months and a few version changes.

    Thread Starter technicalx

    (@technicalx)

    This is still an issue I’m waiting on a fix for.

    Plugin Author Addressfinder

    (@abletech)

    Thanks for submitting your concern.

    I can confirm that our extension has been added in the recommended way according to the official documentation.

    If any further concerns, you are welcome to view our source code, the extension is open source.

    Thanks,
    The Addressfinder team

    Thread Starter technicalx

    (@technicalx)

    no you’ve made a mistake.

    Thread Starter technicalx

    (@technicalx)

    Not resolved, this plugin issue shows up on default wordpress + woocommerce in my testing.

    Plugin Author Addressfinder

    (@abletech)

    Thanks for your continuous testing. Could you please contact us at [email protected]? Thanks

    Thread Starter technicalx

    (@technicalx)

    I have set up a staging and emailed you logins which will expire in 48 hours.

    If you don’t get to it by then the steps are simple, as I said – install Woocommerce + addressfinder, go to payments tabs = see problems

    Thread Starter technicalx

    (@technicalx)

    I got an answer. It was done ages ago is why it’s wrong now.

    Our developers have had a look at it. 

    The explanation is that initially, when the Addressfinder plugin was created, there was no way for WooCommerce plugins to have a configuration section anywhere. The Addressfinder plugin was therefore made to show up on those pages. However, they confirm that this is not a security issue.

Viewing 12 replies - 1 through 12 (of 12 total)
  • The topic ‘options showing up on ALL woocommerce Checkout tabs’ is closed to new replies.