Support » Plugin: Flexible Checkout Fields for WooCommerce » Malicious Account created again

  • Resolved monkriss

    (@monkriss)


    I mentioned in the previous chain about an account being made admin with a file being uploaded to the media library.

    Since then you have created a plugin update and i’m all updated. However, again a new user is now created with Admin privileges and uploaded a file.

    Is there something I missed or is this still broken?

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Support Marta Pawlonka

    (@martapaw)

    Hello @monkriss,

    Did you read our article about this problem and do everything we suggest?
    https://www.wpdesk.net/blog/flexible-checkout-fields-vulnerability/

    If so you still experience this problem, please contact us directly because we need to check your website by admin panel: https://www.wpdesk.net/get-support/.

    Best regards,
    Marta

    Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    *Reads*

    @monkriss Even if you elect to contact anyone on another site, do not permit them to access your admin dashboard.

    @martapaw Please do not make that ask of any user anywhere. The users here are not your customers. They are your open source collaborators and that access is not permitted. It’s one of the conditions for hosting your plugin here. Using off forum to get around that restriction is a problem and can jeopardize your plugin here.

    Please note: I am not accusing you or anyone of any ill will. I 100% know you want to help your user solve their problem. But please take this seriously and do not use that off forum contact to request access to a user’s dashboard.

    There are many ways to get information you need and accessing the user’s site is not one of them. That’s going too far.

    You get the idea.

    Volunteer support is not easy. But these forums need to a safe place for all users, experienced or new. Accessing their system that way is a short cut that will get you into real trouble in these forums.

    • This reply was modified 4 months ago by Jan Dembowski. Reason: Grammar
    Plugin Support Marta Pawlonka

    (@martapaw)

    As we haven’t got any replies, I’m marking this topic as resolved for now.

Viewing 3 replies - 1 through 3 (of 3 total)
  • You must be logged in to reply to this topic.