• Well, I wrote the below comment, then later find out how to prevent the access by changing this setting

    (Require Login To Checkout If ticked then user needs to be logged in to view or pay invoice, can only view or pay their own invoice. If unticked then anyone can view or pay the invoice.)

    so ignore the comment!!!

    the invoices are public, any one have the link can access it without logging to the website, even making the website private other users still can access other users invoices!!!!!!

    • This topic was modified 5 months, 3 weeks ago by majd9.
    • This topic was modified 5 months, 3 weeks ago by majd9.
Viewing 1 replies (of 1 total)
  • Plugin Author Stiofan

    (@stiofansisland)

    Hi @majd9,

    I am glad you figured this out! I hope there is something we can do to reach 5* 🙂

    Just for clarification, when “public” invoices can be viewed by direct link, but these require the key to be known in the URL, this is not something that can be “guessed” so in theroy they are secure unless the direct URL is shared.

    Thanks,

    Stiofan

Viewing 1 replies (of 1 total)

You must be logged in to reply to this review.