Massive security issue

This topic contains 22 replies, has 4 voices, and was last updated by  Stiofan O’Connor 4 years, 5 months ago.

We have moved to a support ticketing system and our forums are now closed.

Open Support Ticket
  • Author
    Posts
  • #511407

    Jan Smolorz
    Full Member
    Post count: 102

    Hi there
    We fall into massive issue here.
    The form is remembering previous user details
    So if somebody filled the form, next person that goes to the site will see all his detials
    http://prntscr.com/ped1ri
    The left browser I filled some info, the right browser is in incognito mode and the information is already there

    There’s blue box above that says:
    Hey, we found a post you started earlier and are showing it below. If you would prefer to start again then please click here to remove this revision.

    I noticed it some time ago when building the site, but I thought it was in my browser cache, or becaus I’m logged in.
    Why would this be stored by your plugin?

    #511415

    Kor
    Moderator
    Post count: 16516

    Hi Jan Smolorz,

    Thanks for your post. GD doesn’t have the functionality to store information. This must be a browser-related and also, this isn’t a known issue. Could you share your Website WP admin access here in private reply so that we could do a test run?

    #511421

    Jan Smolorz
    Full Member
    Post count: 102

    How could browser on remote computer remeber my data?
    Doesn’t make sense.
    I have disabled autoptimize plugin and this seem to disappear though.
    Still how caching plugin could make the form to remember this sort of data?

    #511476

    Guust
    Moderator
    Post count: 29970

    You are the same person using the same computer. Incognito mode still remembers data from non-incognito sessions, but not the other way round normally.

    Browsers across computers can remember data if you have selected to sync your browsers when being logged in as the same user.
    Try using a browser you never use. Also, caching plugins do not remember user data.

    #511480

    Jan Smolorz
    Full Member
    Post count: 102

    we are talking about some random people not my own browsers
    and in this case this was caching plugin
    so I bet it’s not the caching plugin issue
    it’s more down to the wpdirectory plugin
    I know you wouldn’t admit, but I never see any form behaving the same

    #511483

    Guust
    Moderator
    Post count: 29970

    Please give the URL [and access details if necessary] so we can see the blue box pop up for us.
    That is just not how it works.

    If you think it works like that, describe exactly how we can recreate it, using 2 different computers of 2 people who do not know each other. It is not a matter of admitting or not, but we need to be able to recreate it, so we need to know exactly how to do that.

    Thanks

    #511490

    Jan Smolorz
    Full Member
    Post count: 102

    I need to know when you will be doing it to enable the caching plugin.
    I don’t want to leave it to long on the website as don;t want people seeing other clients details

    #511544

    Guust
    Moderator
    Post count: 29970
    This reply has been marked as private.
    #511553

    Jan Smolorz
    Full Member
    Post count: 102

    ICan’t replicate it atm
    I did update of your plugin last night maybe this helped?
    Not sure.
    Will check again bit later

    #511555

    Kor
    Moderator
    Post count: 16516

    Hi Jan,

    Thanks for your reply. If it still doesn’t work, maybe you can test it with another browser. Well, this is definitely not a known issue and it seems to be isolated to your side for some reason. Let us know how it goes.

    Thanks!

    #511639

    Jan Smolorz
    Full Member
    Post count: 102
    This reply has been marked as private.
    #511644

    Stiofan O’Connor
    Site Admin
    Post count: 22956

    Hi Jan,

    We would need to look at your site to check things, please provide wp-admin details when you can.

    Are the users logged in or out when adding a listing?
    Thats the only thing i can think of, as when a listing is added when logged out it creates a unique key so they can still edit it even if they close the window and open it again, if your server is somehow caching session (bad) then thats the only thing i can think of.

    If not please give a step by step guid on how to recreate.

    Thanks,

    Stiofan

    #511869

    Jan Smolorz
    Full Member
    Post count: 102

    Caching was on. Now is not.
    Since when cached session can be showed to random user? Never seen that in woocommerce or other plugins

    https://wpgeodirectory.com/support/topic/some-images-disappear/page/2/

    Here are my login details for FTP and wp-admin

    #511880

    Guust
    Moderator
    Post count: 29970
    This reply has been marked as private.
    #511888

    Jan Smolorz
    Full Member
    Post count: 102
    This reply has been marked as private.
Viewing 15 posts - 1 through 15 (of 23 total)

We have moved to a support ticketing system and our forums are now closed.

Open Support Ticket