Flaw in WP generated error page?
-
Here is the problem:
One of the recommended security measures is to password-protect the wp-admin folder (via .htaccess).
When a WP Error page is generated (say, if you didn’t enter a required field in a comment post), a password prompt will pop up because the error page is requesting wp-admin/css/install.css in it’s HTML, which it can’t get from the password protected directory.
Why does WP generate a WP Error page that is shown to the public that requires files from the wp-admin directory? That seems like it would be a security problem.
Does anyone know how to password protect the wp-admin directory via .htpasswd but still allow access to files/directories that WP needs for this and other pages shown to the public?
Apologize if this has already been answered. Appreciate any help/info.
- The topic ‘Flaw in WP generated error page?’ is closed to new replies.