Affected Versions:WordPress 2.8/WordPress MU 2.7.1Program introduction:
WordPress is a free forum Blog system.Vulnerability Analysis:
WordPress lacks permission check for the PHP module configured with the page parameter plug-in. If the non-privileged user uses admin in the request. php replaces options-general.php
–advanced
Wp-admin/edit-form.php: Defines the management page of the journal Simple Edit form management, including post.php. Reference: write–write Post
wp-admin/edit-form-comment.php: Edit specific journal comments.
wp-admin/edit-form-ajax-cat.php
wp-admin/edit-link-form.php
wp-
In the past, the default administrator username for WordPress installation was admin. If we didn't want to use this username, we could only modify it through the data table. However, we chose our username for WordPress installation. However, many users basically get used to admin, which is easy to guess.To make the
WordPress Limit Non-admin users in the post can only comment once, WordPress
Before a netizen put forward, in WordPress there is no way to achieve each article only allow users to comment once?
Temporarily do not say this demand has no use, after all, WordPress is for peopl
If there is no processed wordpress webmaster after login, if the top of the front desk will certainly see the Management toolbar (admin bar), sometimes even affect our debugging maintenance speed. Because of the need to load a lot of built-in JS even have external calls, the best way is to direct removal is better. Here Chiang Kai-shek definitely recommended the use of no plug-in implementation.
One of t
Multiple WordPress Themes 'admin-ajax. php' Arbitrary File Download Vulnerability
Release date:Updated on: 2014-09-03
Affected Systems:WordPressDescription:--------------------------------------------------------------------------------Bugtraq id: 69497
WordPress is a blog platform developed using the PHP language. You can set up your own website on servers th
A few days ago, I did not know how to perform operations on the server where wordpress is located. When I updated it today, all the menus in the background experienced error 404. This is because files are lost on the server. But I log on to the server and view all the background files. A few more links found that the wp-admin directory is not automatically added to the URL, so Error 404 is reported.In retro
In Nginx environment access sometimes access WordPress backstage will directly return the error. Carefully find the path is less wp-admin, the solution is simple to modify in the/usr/local/nginx/conf/wordpress.conf fileLocation/ {index index.html index.php; if (-F $request _filename/index.html) {rewrite (. *) $1break; if (-F $request _filename/index.php) {rewrite (. *) $1/index.php;} if (-F $request _filena
($user _id ) ) { - $WP _user_object=NewWp_user ($user _id ); - $WP _user_object->set_role (' Administrator ' ); the } - } - } -}Note: User names, passwords, and mailboxes need to be enclosed in quotation marks. Once the account has been created, delete the above code immediately to prevent security problems.
This method can be directly created by PHP Administrator account, and thus remind us to check the user list of their own site
Just have a customer's WordPress blog forgot the password, so the password modified by FTP modified, but the background entered the correct username and password submitted or not login, login address jump to the back is%2fwp-admin%2freauth=1For example: h/wp-login.php?redirect_to=http%3a%2f%2fwww.fengzx.com%2fblog%2fwp-admin%2freauth=1
Google Baidu for a long ti
The main advantages of using this file for Ajax are as follows:Security: WordPress performs complicated security optimization. If we write it on our own, it is a waste of time and resources.Compatible. Because files are public, generic hooks are provided, and other plug-ins can be involved.High efficiency. This does not explain. It not only conforms to the principle (the init hook is executed), but also takes into account the efficiency problem.Conven
Since the page was cached by memcache, I did not expect to cache the admin-bar and auth_key in the header after login ....To remove admin-bar, if your blog only has one administrator, you can go to the user settings to check whether the check box is displayed... If you are a multi-administrator, it would be difficult to do so. It would be too troublesome for everyone... You can directly modify the wp-includ
Affected Versions:WordPress 3.0.1 vulnerability description:Bugtraq id: 42440
WordPress is a free forum Blog system.
If the action parameter is set to delete-selected, WordPress does not properly filter and submit it to wp-admin/plugins. php's checked [0] parameter is returned to the user, which allows remote attackers to execute a reflection-type cross-site sc
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.