• dmbware

    (@dmbware)


    I need a way to block admin users in WordPress from being able to view the public_html folder on the server. There are many ftp downloads out there that can be downloaded that will show the entire directory.

Viewing 5 replies - 1 through 5 (of 5 total)
  • esmi

    (@esmi)

    This is not a WordPress issue. Contact your hosting provider.

    Thread Starter dmbware

    (@dmbware)

    This is not a Hosting issue this is a security issue on WP. If a developer is running a system for a client and they happen to have /blog loaded with wordpress. The wordpress user can load in FTP and download and delete files within that public directory. That is a major security issue for developers.

    tgiokdi

    (@tgiokdi)

    so you’re users are able to log into your ftp server with their wordpress user/pass? the two systems are completely independent of each other, and I just cant’ see how that could possibly happen.

    Thread Starter dmbware

    (@dmbware)

    A word-press user can download FTP into wordpress via plugin and somehow it gives them full access to the entire root directory of that account without having to know ftp credentials. I have no idea how it works, but to me it doesn’t seem right.

    what plugin?

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Stop Admin users in WP from Using FTP’ is closed to new replies.