EDD Discount code Flaw? (Invalid emails can be used!)
-
EDD V. 2.6.6
EDD – Mail Chimp V 2.5.6I am offering certain tracks for free (one per customer with a download limit set)
This is the process that happens.
1. Customer clicks on a free track link on my website.
2. Customer is taken to a subscription page via MailChimp.
3. Customer subscribes.
4. Customer receives email to verify subscription.
6. Customer is then taken to a Mail Chimp campaign that contains the discount code and link to the tracks.
7. Customer picks a valid track, enters discount code / details and the success page with the appropriate download link appears.My concern is the customer can pick another track, enter the same discount code and enter any invalid email and names in the required fields etc i.e. (Email = [email protected] Name = E Surname = E tick accept terms and conditions and the success page comes up with another download link) With an invalid email I do not know who is getting the free tracks…
Is there any more secure ways to do this please? (I really want make sure everything is valid and one customer can only download one valid free track)
Thanks for any advice…
- The topic ‘EDD Discount code Flaw? (Invalid emails can be used!)’ is closed to new replies.