Support » Plugin: WP-Members Membership Plugin » [Plugin: WP-Members] Member login not required in RSS feed

  • Resolved


    Hi there,

    I’ve successfully installed the WP-Members plug-in and it works fine. However if I subscribe to RSS feeds (via Outlook) I can see all the posts (normal ones as well as the ones requiring user login).

    Correct me if I’m wrong but this is quite a big security hole, right?

    Any idea how to tackle this?
    Thanks in advance!

    Lucky Luke

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author Chad Butler


    It’s a big security hole if you don’t set your feeds to “Summary”

    Take a look at your current WP feed settings. Under Settings > Reading, I recommend that “For each article in a feed, show” should be set to “Summary.” Current versions of WP install with this set to “Full text” by default so you need to change it.

    (Incidentally, this should register as a warning message at the top of the plugin’s admin panel unless you have checked the plugin option “Ignore warning messages.” It’s also covered under “Locking down your site” in the installation instructions: )

    You can also gain a little more control over your feed excerpts leveraging some built-in WP functions. Here are a couple examples:

    add_filter('excerpt_length', 'chg_excerpt_length');
    function chg_excerpt_length($length)
       // set the number to whatever number of
       // words you want the excerpt to be.
       return 20;
    add_filter('the_excerpt_rss', 'get_excerpt_len');
    function get_excerpt_len()
       $content = the_content;
       $len = strpos($content, 'more');
       $len = $len-10;
       return $len;

    Hope that helps.

    Sorry, I’m a newbie with WordPress and found this plug-in very useful, but had the same problem as luckyluke.

    Then I saw your examples cbutlerjr, ok, but maybe stupid question: where to add this code?

    Thanks in advance!

    Thanks cbutlerjr! The summary checkbox does the trick for me.

    Plugin Author Chad Butler


    LuckyLuke – good to hear.

    Todder – no problem. Generally, your theme will have a functions.php file. You can use this to load and call these types of WP hooks, filters, and actions. But the first thing is that you should begin with using the RSS summary setting. The code is specifically if you need more control over your feed excerpts than the default.

    Thanks cbutlerjr, this thing with the summary setting I did right from the beginning.
    And I’m using the more-tag in my articles. Inside the blog it is working fine, but in the feed the whole article is displayed.
    I’m using the free version of PageLine, maybe there is a setting which could not be changed easily …
    I’ll check this tonight!

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘[Plugin: WP-Members] Member login not required in RSS feed’ is closed to new replies.