• I installed MainWP few days ago and yesterday found this security fault that expose all my sites:
    If any one create an user and make login on the Main site, even if you limit new users as a ‘subscribers’, they will have access to ALL SITES Dashboard if you leave the main site dashboard open to them.
    I’m using two different roles plugin to protect areas I don’t want subscribers to go, but neither one protects MainWP
    I just removed everything and I would say everyone should to the same until this issue is settle.

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author mainwp

    (@mainwp)

    Thanks for your feedback. As noted in installation step 1, your Dashboard should be on a dedicated site for only your Dashboard which means only you should have access not users or subscribers.

    “We HIGHLY recommend a NEW WordPress install for your MainWP Dashboard. Using a new WordPress install will help to cut down on Plugin Conflicts and other issues that can be caused by trying to run your MainWP Main Dashboard from an active site. Most hosting companies provide free subdomains (“demo.yourdomain.com”) and we recommend creating one if you do not have a specific dedicated domain to run your Network Main Dashboard. If you are not sure how to set up a subdomain here is a quick step by step with cPanel, Plesk or Direct Admin. If you are not sure what you have, contact your hosting companies support.”

    With the next update we will look into limiting access to the MainWP section to Admins only in order to help if a Dashboard gets installed on a site that has active subscribers.

    If anyone sees anything they consider a security issue we encourage you to use the White Hat Reward section to share your information so that you are eligible for a reward. It is our ongoing effort to provide the most secure experience possible to our users we are offering a reward for each security vulnerability reported in the MainWP Plugin System.

    Plugin Author mainwp

    (@mainwp)

    Added only Admins can see Dashboard in version 1.2.1 – Changelog

    Thread Starter ehm01

    (@ehm01)

    Added only Admins can see Dashboard in version 1.2.1

    Great… I will try it again! ??

    Thread Starter ehm01

    (@ehm01)

    I’m reviewing my review…
    After the issue has been address by the programmer, looks like it’s safe now, and I’m changing my 1 star to at least 4.
    Give me couple more weeks to evaluate it better and maybe will be a 5 star!!!
    Thank you for the prompt taking care of the problem.

    brad1004

    (@brad1004)

    Hi ehm01

    I was wondering how your evaluation of MainWP is coming along?

    Any updates would be appreciated

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Security fault on MainWP’ is closed to new replies.