security issue with allowing users to map their own domains
-
Note there is a security hole in this plugin where if a user is allowed to map their own domains via the wp-admin tools interface, they can just enter a subdomain of the current wordpress network and take it over.
So for example if www.ads-software.com was running mu and this plugin and you were at blah.www.ads-software.com and the admin menu was active, they can map news.www.ads-software.com over their blog
There needs to be a security check that that the domain they entered is not a subdomain of the current network, even if it is not active.
https://www.ads-software.com/plugins/wordpress-mu-domain-mapping/
Viewing 5 replies - 1 through 5 (of 5 total)
Viewing 5 replies - 1 through 5 (of 5 total)
- The topic ‘security issue with allowing users to map their own domains’ is closed to new replies.