Further restrict access for temporary admins
-
Make it configurable, perhaps, but I think in most cases third-party developers given access for technical troubleshooting are not meant to have read access to the user base of a WordPress install so it seems the default should be blocked.
In many countries now you are not supposed to give third parties access to user data which they have nothing to do with and not without signing a contract with them even if they do, etc.
Blocking users.php would also block the far reaching access otherwise possible through popular plugins like User Role Editor.
plugin-install.php and theme-install.php should probably also be blocked by default as the typical use case would seem to be asking third-party devs to look into problems with existing plugins or themes rather than asking them to install new themes and plugins on behalf of the owner.
After all, if a WP owner doesn’t know how to install a plugin himself, we can assume he also doesn’t know how to install your plugin in order to let others do it.
- The topic ‘Further restrict access for temporary admins’ is closed to new replies.