Title: hidden url
Last modified: February 12, 2024

---

# hidden url

 *  Resolved [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 4 months ago](https://wordpress.org/support/topic/hidden-url-4/)
 * The set hidden url is exposed when the data export tool from wordpress is used.
 * wordpress – tools – export personal data – send personal data export confirmation
   email.
 * confirmation email received by customer shows the hidden url in browser when 
   the email is confirmed.

Viewing 15 replies - 1 through 15 (of 19 total)

1 [2](https://wordpress.org/support/topic/hidden-url-4/page/2/?output_format=md)
[→](https://wordpress.org/support/topic/hidden-url-4/page/2/?output_format=md)

 *  Plugin Support [MaximeWPS](https://wordpress.org/support/users/seinomedia/)
 * (@seinomedia)
 * [2 years, 4 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17425054)
 * Hello,
 * Thanks for using WPS Hide Login.
 * If your customers can sign up, log in and request their data, it means they know
   the login URL, isn’t it ?
 *  Thread Starter [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 4 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17425067)
 * No, this is not necessarily true. We run a woocommerce shop and choose to hide
   the admin URL.
 * Users can only create an account by placing an order.
 *  Thread Starter [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 4 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17425090)
 * The problem arises when a site administrator goes to… tools -> export personal
   data on the wp dashboard and enters an email address and sends the notification
   to the user.
 * if the user then presses confirm in the received email, the URL in the browser
   will change to the hidden URL.
 * This needs to be resolved. Good luck ! 😀
 *  Plugin Support [MaximeWPS](https://wordpress.org/support/users/seinomedia/)
 * (@seinomedia)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17426997)
 * Hello,
 * Can you share you website URL, please ?
 *  Thread Starter [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17427041)
 * That’s not necessary, the steps to reproduce the problem are above. I’m just 
   reporting an issue.
 *  Plugin Support [MaximeWPS](https://wordpress.org/support/users/seinomedia/)
 * (@seinomedia)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17427232)
 * As you want.
 * But this is not an issue. As there is a user account, this one is supposed to
   be able to log in and then, to know the login URL.
 * The fact you create user accounts without giving the right to log in is a specific
   operating mode which isn’t compatible with the way th plugin works.
 *  Thread Starter [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17427262)
 * If you are familiar with Woocommerce, you understand that users log in in a different
   way than via the standard WP login screen. So of course they have the right to
   log in. But I understand your position on your plugin. And you have the right
   to leave it functioning as it is. I will therefore mark the topic as resolved.
 *  Thread Starter [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17427276)
 * But I’m just wondering what the purpose of your plugin is in this case. a hidden
   url that isn’t hidden is a strange thing.
 *  [bubulgum](https://wordpress.org/support/users/bubulgum/)
 * (@bubulgum)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17473433)
 * Hi, 
   I just download and install your plugin (which in principle is brilliant!),
   and I have the same issue.I think you haven’t understood what [@wpsupacc](https://wordpress.org/support/users/wpsupacc/)
   has explained to you… and yes, it’s a real issue that needs to be solved, otherwise
   your plugin is unfortunately useless ^^ (except if no-one, never, ask to consult
   his personal data… unlikely to ever happen 😜)
 * So, I’ve followed the _steps to reproduce_ wrote by [@wpsupacc](https://wordpress.org/support/users/wpsupacc/).
   
   _for a reminder: _Because of RGPD in UE or any data protect laws all around the
   world, anyone (let’s say the “user”) can contact a website (let’s say the “webmaster”),
   and tell that he (user) would like to know which of his personal data you (webmaster)
   have access to, via the website.[https://www.cnil.fr/en/rights-and-obligations](https://www.cnil.fr/en/rights-and-obligations)
 * To satisfy the request of the user, the webmaster has to follow the following
   process:
    - On the wp dashboard, to go to tools -> export personal data and enter the 
      email address of the user who contact you to assert his rights.
    - WordPress will the send an email to the user, with a link he has to click,
      to confirm his request. The link looks like this: 
      [https://www.nameofyourwebsite.com/](https://www.nameofyourwebsite.com/)**
      wp-login.php**?action=confirmaction&request_id=235708&confirm_key=e1SASfwUv9aP7paQn4Bt
    - When the user click the link (to confirm his request), the URL in the browser
      will change to the hidden URL, and will look like this: 
      [https://www.nameofyourwebsite.com/](https://www.nameofyourwebsite.com/)**
      YOURHIDDENURL**/?action=confirmaction&request_id=235708&confirm_key=e1SASfwUv9aP7paQn4Bt(
      Do you see the problem now? 😊)
    - Afterwards, the webmaster receives a notification that the user’s request 
      has been confirmed (as the user click the link… and now knows the secret login
      url ^^), and he (webmaster) can then, depending on the user’s request, either
      send him a copy of his personal data, or delete them.
      Official WordPress guide:
      [https://wordpress.org/documentation/article/tools-export-personal-data-screen/](https://wordpress.org/documentation/article/tools-export-personal-data-screen/)
 * This is law. And anyone can ask any website about his “presumed personal data”(
   for making my test, I’ve entered one of my email address (XXX), that has nothing
   to do with one of my websites (YYY)… so, no data found… but in the email (on 
   XXX) received from WordPress, there was the confirmation link… which redirect
   on the hidden url of the YYY website!)
   So it’s a very easy way for a hacker to
   know your login page url… that’s why this is a real issue, and this need to be
   solved, otherwise… the main (and only!) goal of your plugin is missed… And it’d
   be a shame, because you did great job! So, you just need to adapt it with those
   new laws about personal data protection (don’t worry, those laws all say quite
   the same 😜), as I see your plugin was created some years before all those laws,
   and it will be perfect 💪🥇✨If you need further informations, don’t hesitate
   to ask me 🤗Kind regards,Jess
    -  This reply was modified 2 years, 3 months ago by [bubulgum](https://wordpress.org/support/users/bubulgum/).
 *  Thread Starter [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17473529)
 * [@bubulgum](https://wordpress.org/support/users/bubulgum/) Thank you for identifying
   the problem and taking the time to explain it in such detail. let’s hope the 
   developer understands 😉
 * Note: changed status of topic to not resolved.
 *  [bubulgum](https://wordpress.org/support/users/bubulgum/)
 * (@bubulgum)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17473566)
 * [@wpsupacc](https://wordpress.org/support/users/wpsupacc/) Thanks for your message
   😊
   Yes, I hope he will understand the problem, because in my opinion, this issue
   makes the use of this plugin dangerous:As you think your website is protected
   by this trick (and others, of course), you think you can reduce your vigilance(
   because you wrongly believe you’ve done everything necessary to securize your
   website). However, this is not the case, and your supposedly “hidden” connection
   url is far too easily accessible.
 *  Thread Starter [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17473615)
 * I totally agree. It is of course possible that the developer has a different 
   intention with his plugin. If so, I would like to hear from him what the intention
   is. I think many users use it with the same thoughts as we do.
 *  Thread Starter [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17473639)
 * @maximewps [@seinomedia](https://wordpress.org/support/users/seinomedia/) Do 
   you understand the problem?, is this going tobe solved? And if not, what is the
   purpose of your plugin ?
 *  [Iamhere](https://wordpress.org/support/users/iamhere/)
 * (@iamhere)
 * [2 years, 2 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17510096)
 * Hello
 * I too want to use this on a site with woocommerce. So – does it hide from users?
 * It looks a nice plugin, please provide some answer. thank you in advance for 
   your kind contribution to the community.
 *  Thread Starter [wpsupacc](https://wordpress.org/support/users/wpsupacc/)
 * (@wpsupacc)
 * [2 years, 2 months ago](https://wordpress.org/support/topic/hidden-url-4/#post-17510144)
 * the answer is no 🙂 if you use woocommerce funtions they will get the hidden 
   url in the mail 🙂

Viewing 15 replies - 1 through 15 (of 19 total)

1 [2](https://wordpress.org/support/topic/hidden-url-4/page/2/?output_format=md)
[→](https://wordpress.org/support/topic/hidden-url-4/page/2/?output_format=md)

The topic ‘hidden url’ is closed to new replies.

 * ![](https://ps.w.org/wps-hide-login/assets/icon-256x256.png?rev=1820667)
 * [WPS Hide Login](https://wordpress.org/plugins/wps-hide-login/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wps-hide-login/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wps-hide-login/)
 * [Active Topics](https://wordpress.org/support/plugin/wps-hide-login/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wps-hide-login/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wps-hide-login/reviews/)

 * 19 replies
 * 4 participants
 * Last reply from: [Iamhere](https://wordpress.org/support/users/iamhere/)
 * Last activity: [2 years, 2 months ago](https://wordpress.org/support/topic/hidden-url-4/page/2/#post-17516458)
 * Status: resolved