• Hi,
    I have just been made aware of an issue with Ultimate Member. We have some members who are displayed publicly in our trainer directory whereas others are only site members privately in the backend. However, when you put in our website url and e.g https://www.mywebsite/user/anyusername
    the profile for individual users will show up even if they are not listed publicly. I have set people up so that they do not have Ultimate Member directory or role i.e. just subscribers, but this does not make a difference.
    Here is an example of a test user https://www.eltas.de/user/tester
    I tried deactivating Ultimate Member and will get a page error code if I put in the same url so I think the issue is with the plugin.I would really appreciate some help here as this is critical with respect to data protection. Thanks in advance.

Viewing 3 replies - 1 through 3 (of 3 total)
  • Thread Starter 007elt

    (@007elt)

    Back again…..I am not sure if I was quite clear and would like to clarify. I set up two roles…”members” one for all users and the other “Fat membrs” for those who would like to appear publicly in the trainer directory. The issues is that member users/profiles could still be found in the trainer directory (although they have not been assigned to it) if you put in a last name after the URL. Thus more details about this person could then be obtained.

    Is it anyway possible for the administrator to hide certain users/profiles so they won’t show up at all? (I know there is capability for individual user to hide his profile, but it would be very difficult for me to get all individuals to do this)I found an old post from several years ago requesting this function, but it wasn’t available and I haven’t found anything else in this regard. Anyway, thanks for any help or ideas on how I could prevent such information from being accessed from the front end (I know it may be unlikely that someone tries typing in people’s names, but it really should not be possible for them to get at information that way when it is supposed to be private).
    I have thought of changing url in user page from name to User-id number or having a different url to “mask” things, but am not sure it that is such a “clean” solution. Thanks.

    • This reply was modified 4 years, 7 months ago by 007elt.
    Thread Starter 007elt

    (@007elt)

    Please note that even if I have made a profile private (and it does not show up on the listing), the user info still shows up if you indicate the https://yourwebsitename/user/anyusername. If you put in the name of a deactivated user after the /user/, the deactivate profile shows up!
    This happens for all users even if they are not assigned an ultimate member role.
    This is definitely not good.
    I can’t simply deactivate the page as then it is not possible to view the individual profiles of trainers who want to be viewed publicly.

    It would be great to have some code here that prohibits this.

    Can other users please check to see if they have the same problem and a developer help here. Thanks.

    Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    @007elt I see no reason to have flagged this topic for moderator review and have removed the flag you set.

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘user url listing private names–problem with Ult. Mem’ is closed to new replies.