Is Custom Post Fields safe for scripting?
-
Hi, i don’t know exactly what it’s called but when we go to edit post, we can see under Custom Fields, key and values that users can enter.
My question would be, how much can i trust that these fields can 1. only be seen by me and 2. only be used and modified by me.
Previously i used shortcodes for parsing any file onto my page. This is a huge security risk, since visitors can simply use my shortcode, and get all files in my system.
Now i still need this functionality, so i found custom fields and thought, that i could add key “file_parse” and value “path/to/my/file.html” to parse it this way. am i missing a vulnerability again or is this fully safe to do?
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
- The topic ‘Is Custom Post Fields safe for scripting?’ is closed to new replies.