• I’ve discovered an interesting bug, or misconceptual error in wordfence.
    If the wordpress site has in its filesystem settings FTPSOCKETS and not direct FS access, wordfence seems to be redirecting to a page that SHOULD ask for some credentials for restoring an original file that it has detected as modified, but it does not.
    In other words, as you can see in this URL part copied from the action it should take upon clicking on “restore original version of this file”
    Wordfence&wfScanAction=promptForCredentials&wfFilesystemAction=restoreFile&issueID=19&nonce=0514d184a5
    it SHOULD ask for some credentials, but it doesn’t. No error is displayed, and the user is redirected to the wordfence dashboard, where the same “N issues found” message is displayed, because the file(s) cannot be restored to their *seemingly* original versions.

Viewing 1 replies (of 1 total)
  • Hi,
    Thanks for reporting this issue to us, I’ve filled a bug report with internal reference number “FB4345” regarding this one, our dev team will investigate it in details and it should be fixed in any of the upcoming updates.

    Thanks.

Viewing 1 replies (of 1 total)
  • The topic ‘Wordfence NOT asking for credentials / cannot restore original file’ is closed to new replies.