• Resolved luizargument

    (@luizargument)


    Hello. I’m using a website with Buddyboss WordPress theme and checking the HTML generated source code I see that HelpieFAQ generates a Javascript with a lot of sensible content related to the current logged in user (even the encrypted password!), like this:

    <script type="text/javascript" id="helpie-faq-bundle-js-extra">/* <![CDATA[ */var helpie_faq_object = {"nonce":"46901afba9","ajax_url":"https:\/\/mywebsite.com\/wp-admin\/admin-ajax.php","current_post_id":"39642","current_user":{"data":{"ID":"456","user_login":"BI002814","user_pass":"$P$BVI2\/yJhKakakak.llxUAQOWDubAew0","user_nicename":"bi002814","user_email":"[email protected]","user_url":"","user_registered":"2023-06-05 13:48:09","user_activation_key":"","user_status":"0","display_name":"MY FULL USER NAME HERE"},"ID":456,"caps":{"subscriber":true,"bbp_participant":true},"cap_key":"wp_capabilities","roles":["subscriber","bbp_participant"],"allcaps":{"read":true,"level_0":true,"spectate":true,"participate":true,"read_private_forums":true,"publish_topics":true,"edit_topics":true,"publish_replies":true,"edit_replies":true,"assign_topic_tags":true,"subscriber":true,"bbp_participant":true},"filter":null},"plan":"free","url":"https:\/\/mywebsite.com\/wp-content\/plugins\/helpie-faq\/","enabled_submission":"1","enable_search_highlight":""};var faqStrings = {"hide":"Hide","addFAQ":"Add FAQ","noFaqsFound":"No FAQ found"};/* ]]> */</script>

    Is this normal?

    I don’t know if this is related to other plugin like W3 Total Cache.

    Using the latest WordPress and Helpie FAQ versions.

Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
  • The topic ‘[Security] Helpie FAQ displaying current user ID and password at HTML source’ is closed to new replies.