Mar 25, 2017 6:50 am
I had logged in as a normal forum user and went to visit wp-admin section of the site, and found that any user can see this page and see what plugins I have installed. Is this a security risk?
2 Replies
Mar 25, 2017 10:48 am
What wpForo version you use? The latest versions don't allow subscribers to access to wpForo information in dashboard.
Mar 25, 2017 11:26 am
If I may add my 2 cents,
To my understanding, wpForo uses WordPress user's data base.
Few times I logged-in to the forum with the admin name and naturally I could see everything including the WP dashboard because I've enabled the admin top bar for admin.
Since then, I've created few test users for different rolls and did not see the issue that you're pointing to.
I'm using 2 browsers - one for admin and the other one for test users.