wp-login.php redirection for ordinary users
-
Hello
Thanks for this plugin, but I have a problem that I’ll explain steps by steps for better understanding what I’m talking about:1- After installing and activating I go to settings and select “Require Approval” = “yes”; “Require Login” = “yes”; “Show Registration Link” = “yes”.
2- Then I go to “add new page” I put some title and then from the dropdown button of Site Reviews I select “submit a review” adding some title as well.
3- Then I open the page from another browser and private windows to see the page as an ordinary user (visitor) and I find the text and link: “You must be logged in to submit a review.”
4- This link redirect users to the wp-login.php or wp-admin dashboard instead to redirecting users to /my-account page from woocommerce or a custom /login page created by others plugins.
I hope you understand that this is a serious lack of security and worst than that is that even installing plugins that hides (changing the name of) wp-login.php from hackers, the link generated from your plugin will redirect visitors to this hidden link.
I tested in my website and even in a fresh new wordpress site and the problem was exactly the same. I think you should add a field on your plugin setting page where users can choose where they want to redirect they visitors when clicking that link.
I’ll really appreciate your help with this issue!
Thanks for your time,
- The topic ‘wp-login.php redirection for ordinary users’ is closed to new replies.