WordPress.org

Ready to get started?Download WordPress

Forums

Absolute Privacy
Absolute privacy enables login without password (5 posts)

  1. art-e-facto
    Member
    Posted 2 years ago #

    After enabling this pluging, you can access the site knowing at least the username, so if you have admin as a username (as many sites are), you just need to put it in the login form and you're done... A very strong security problem!!

    http://wordpress.org/extend/plugins/absolute-privacy/

  2. dsburdette
    Member
    Posted 2 years ago #

    Same issue here. EVERY site I'm using this plugin is now broken. HUGE problem. Now I have to find another lockdown solution. Bummer, because I like this plugin. Any recommendations?

  3. esmi
    Forum Moderator
    Posted 2 years ago #

    if you have admin as a username

    You shouldn't be using admin as user name - precisely because many sites are.

  4. dsburdette
    Member
    Posted 2 years ago #

    I'm not using admin as a username. The plugin is broken and it will be forever as the author is no longer supporting the plugin. Read more on his blog:

    http://www.johnkolbert.com/site-news/the-official-goodbye/

    However, I found if you simply want a full lockdown on your site and to redirect all users to the login page, you must make sure this plugin is completely deactivated or not installed at all and simply add this code to the header of your active theme.

    <?php
    /*
    Checks to see if the visitor is logged in. If not,
    they are redirected to the login page.
    */
    if ( !is_user_logged_in() ) {
        auth_redirect();
    }
    ?>

    This is only useful if you want no pages visible to unauthorized users. There are other Members-only plugins that give you more granular control on a per page/post basis. I, however, was looking for full lockdown, like an extranet might be.

  5. Eric Mann
    Member
    Plugin Author

    Posted 2 years ago #

    The plugin has been patched as of version 2.0.6 to fix this vulnerability.

Topic Closed

This topic has been closed to new replies.

About this Plugin

About this Topic