Massive security issue
This topic contains 22 replies, has 4 voices, and was last updated by Stiofan O’Connor 5 years, 1 month ago.
We have moved to a support ticketing system and our forums are now closed.
Open Support Ticket-
AuthorPosts
-
October 3, 2019 at 1:24 pm #511407
Hi there
We fall into massive issue here.
The form is remembering previous user details
So if somebody filled the form, next person that goes to the site will see all his detials
http://prntscr.com/ped1ri
The left browser I filled some info, the right browser is in incognito mode and the information is already thereThere’s blue box above that says:
Hey, we found a post you started earlier and are showing it below. If you would prefer to start again then please click here to remove this revision.I noticed it some time ago when building the site, but I thought it was in my browser cache, or becaus I’m logged in.
Why would this be stored by your plugin?October 3, 2019 at 2:16 pm #511415Hi Jan Smolorz,
Thanks for your post. GD doesn’t have the functionality to store information. This must be a browser-related and also, this isn’t a known issue. Could you share your Website WP admin access here in private reply so that we could do a test run?
October 3, 2019 at 2:27 pm #511421How could browser on remote computer remeber my data?
Doesn’t make sense.
I have disabled autoptimize plugin and this seem to disappear though.
Still how caching plugin could make the form to remember this sort of data?October 3, 2019 at 7:26 pm #511476You are the same person using the same computer. Incognito mode still remembers data from non-incognito sessions, but not the other way round normally.
Browsers across computers can remember data if you have selected to sync your browsers when being logged in as the same user.
Try using a browser you never use. Also, caching plugins do not remember user data.October 3, 2019 at 7:30 pm #511480we are talking about some random people not my own browsers
and in this case this was caching plugin
so I bet it’s not the caching plugin issue
it’s more down to the wpdirectory plugin
I know you wouldn’t admit, but I never see any form behaving the sameOctober 3, 2019 at 7:35 pm #511483Please give the URL [and access details if necessary] so we can see the blue box pop up for us.
That is just not how it works.If you think it works like that, describe exactly how we can recreate it, using 2 different computers of 2 people who do not know each other. It is not a matter of admitting or not, but we need to be able to recreate it, so we need to know exactly how to do that.
Thanks
October 3, 2019 at 8:00 pm #511490I need to know when you will be doing it to enable the caching plugin.
I don’t want to leave it to long on the website as don;t want people seeing other clients detailsOctober 4, 2019 at 6:21 am #511544This reply has been marked as private.October 4, 2019 at 6:46 am #511553ICan’t replicate it atm
I did update of your plugin last night maybe this helped?
Not sure.
Will check again bit laterOctober 4, 2019 at 6:56 am #511555Hi Jan,
Thanks for your reply. If it still doesn’t work, maybe you can test it with another browser. Well, this is definitely not a known issue and it seems to be isolated to your side for some reason. Let us know how it goes.
Thanks!
October 4, 2019 at 4:32 pm #511639This reply has been marked as private.October 4, 2019 at 5:10 pm #511644Hi Jan,
We would need to look at your site to check things, please provide wp-admin details when you can.
Are the users logged in or out when adding a listing?
Thats the only thing i can think of, as when a listing is added when logged out it creates a unique key so they can still edit it even if they close the window and open it again, if your server is somehow caching session (bad) then thats the only thing i can think of.If not please give a step by step guid on how to recreate.
Thanks,
Stiofan
October 7, 2019 at 8:20 am #511869Caching was on. Now is not.
Since when cached session can be showed to random user? Never seen that in woocommerce or other pluginshttps://wpgeodirectory.com/support/topic/some-images-disappear/page/2/
Here are my login details for FTP and wp-admin
October 7, 2019 at 8:50 am #511880This reply has been marked as private.October 7, 2019 at 8:56 am #511888This reply has been marked as private. -
AuthorPosts
We have moved to a support ticketing system and our forums are now closed.
Open Support Ticket