• hello,

    When you mouse over the author’s name, it shows my login screen name!

    That’s a total security vulnerability. It’s giving the hacker half the information they need to crack the username/password combination.

    Fortunately, I set very strong passwords. But still. This is crazy!

    How do I set things up so that the “author” name of the article is NOT the same as the login name. This is a one-person-doing-the-whole-thing website. I can set or destroy any “person” with any permission level. Or add a new person.

    Looking for a step-by-step, can’t miss instruction set like:

    1) Log into your wordpress site
    2) go to this exact page, located in settings>>accounts>>whatever
    3) do this exact thing
    4) hit save
    5) go to this exact page, located in users>>general>>login
    6) add this
    7) subtract that
    8) hit save

    Thank you.

Viewing 5 replies - 1 through 5 (of 5 total)
  • That’s a total security vulnerability.

    No it isn’t.

    If you are that worried about this issue as a matter of security, and given that you’ve established that you run a one-person site, I would simply remove the link to the author archive, and simply output the author display name.

    Thread Starter wp beginner

    (@wp-beginner)

    Yes it is @esmi

    @chip: how do you do this step-by-step?
    That sounds awesome.

    I’d need to see the relevant template file(s) in order to give you step-by-step instructions.

    (But I do agree with esmi: it’s not a significant security vulnerability. Most would-be hackers will simply hammer on the username admin, anyway.)

    Thread Starter wp beginner

    (@wp-beginner)

    I figured it out.

    Hacked at the code till it gave up.

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Security question regarding author's post name’ is closed to new replies.