• Resolved alejandrovalenciaw

    (@msiasus1234)


    Hello, I have encountered a serious security problem.
    When you log in the data is not encrypted when sent by admin-ajax.php
    I am attaching a screenshot of the problem.

    Ejemplo

    The page I need help with: [log in to see the link]

Viewing 11 replies - 1 through 11 (of 11 total)
  • Plugin Author RadiusTheme

    (@techlabpro1)

    Hello,

    I just check your issue.

    Thank you for noticing this important issue.

    Can you please let us know why I need to encrypt your password as we are using nonce for security and also all the WordPress security checks at the backend?
    Also, Ajax requesting the same site.

    For now, we are checking all the WordPress security at the backend also your password is already is encrypted at the backend.

    Can you please explain? if we find a security issue from your explanation we will change our login system.

    Thank you for your valuable information

    Thank you

    Thread Starter alejandrovalenciaw

    (@msiasus1234)

    Spyware that gets hooked on browsers can use the password. Also many users use the same password for different web pages so their password when entering the site would be exposed.
    Also the laws of EUROPE LOPD (Organic Law on Protection of Personal Data) oblige us to increase security, for which we risk exorbitant fines.

    My business belongs to Spain and it affects me

    Just encrypting the password would be enough to avoid major problems.

    thank you

    Plugin Author RadiusTheme

    (@techlabpro1)

    Ok thank you for your detailed description, we will encrypt the password at our next version at the HTTP request.

    Thank you

    Thread Starter alejandrovalenciaw

    (@msiasus1234)

    Thanks to you

    Plugin Author RadiusTheme

    (@techlabpro1)

    The security issue is fixed at our new version 1.3.13

    Thanks

    Hi! I have the classist theme and the classified listing pro plugin, how do I update the plugin if it still doesn’t appear to update?

    Plugin Author RadiusTheme

    (@techlabpro1)

    @barretomariadesign Just released classilit theme new version please update.

    I do not see the pending update.

    I was able to update, anyway the username and password are still displayed.

    Plugin Author RadiusTheme

    (@techlabpro1)

    @barretomariadesign have you updated Classified Listing Pro plugin to 1.5.71 ?

    For Theme support please create ticket from our website.

    Yes, both theme and plugins, but ajax admin password and username are still showing. Ok, I’ll create a ticket.

Viewing 11 replies - 1 through 11 (of 11 total)
  • The topic ‘Security issue when logging in’ is closed to new replies.