• Resolved Jason

    (@larceniii)


    There is a .css file in backup.php that’s included in the header of the manual backup status page that links to songpane.com

    This file isn’t even on their server and results in a 404 error on their website.
    The referrer url could be disclosed via analytics (webtracking) software to the operator of the songpane website.

    This is the exact link in your source
    <link rel="stylesheet" id="install-css" href="http://songpane.com/wp-admin/css/install.css" type="text/css" media="all" />

    Just needs to be localized, or preferably gone all together.

    http://wordpress.org/extend/plugins/backup/

    [No bumping, thank you.]

Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
  • The topic ‘Problem with Referrer Manual Backup URL disclosure’ is closed to new replies.