• Resolved ultralite

    (@ultralite)


    Hello, I have a problem with your plugin, every time I activate it appears in the code of the main page the url of the administrator.
    The administrator area I have it hidden, this should not appear, the domain name is an example.
    I think your plugin has a security bug.

    /* <![CDATA[ */
    var sdm_ajax_script = {“ajaxurl”:”https:\/\/www.example.com\/wp-admin\/admin-ajax.php”};
    /* ]]> */

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi,

    What happens if you type the following URL in your browser?

    https://www.example.com/wp-admin/admin-ajax.php

    I carried out a test in my dev site. I added a new download button in my dev site. I then used a different browser for testing purposes. Yes, I can see the code you mentioned above. Then I decided to type the URL in the same browser and all I can see is 0 in the page and also when viewing the browser source code. Of course I replaced www.example.com with my domain name.

    Regards

    • This reply was modified 4 years, 10 months ago by mbrsolution.
    • This reply was modified 4 years, 10 months ago by mbrsolution.
    • This reply was modified 4 years, 10 months ago by mbrsolution.
    • This reply was modified 4 years, 10 months ago by mbrsolution.
    Thread Starter ultralite

    (@ultralite)

    Correct, it appears 0.
    Anyway your plugin does not work for me at this time, I need certain files can only be downloaded by putting a password, the visitor to request to download the file, you must request a password and the plugin sends a password to download it, and I see that this functionality does not have your plugin.
    Thanks for your support.

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, we do have the following method to password protect the download file.

    https://simple-download-monitor.com/how-to-password-protect-your-wordpress-downloads/

    And also the following method as well.

    https://simple-download-monitor.com/offering-downloads-to-logged-in-users-members-only/

    Also, can you consider adjusting your 1 star review since the plugin works and it does exactly what it says in the details page.

    Thank you.

    • This reply was modified 4 years, 10 months ago by mbrsolution.
    Thread Starter ultralite

    (@ultralite)

    Yes, not at all, it should not show the admin URL in the source code even if it says 0 if you try to enter, my review I change it of course.

    thank you very much.

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, I have submitted a message to the plugin developers to investigate further your findings.

    Thank you.

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘url admin’ is closed to new replies.