Notifications
Clear all

wpForo 1.x.x [Closed] Normal Users Accessing wp-admin

3 Posts
3 Users
1 Reactions
1,395 Views
Posts: 10
Topic starter
(@trees)
Eminent Member
Joined: 8 years ago

I had logged in as a normal forum user and went to visit wp-admin section of the site, and found that any user can see this page and see what plugins I have installed. Is this a security risk?

2 Replies
Robert
Posts: 10590
Admin
(@robert)
Support Team
Joined: 9 years ago

What wpForo version you use? The latest versions don't allow subscribers to access to wpForo information in dashboard.

Posts: 316
(@1sharonkat)
Reputable Member
Joined: 8 years ago

If I may add my 2 cents,
To my understanding, wpForo uses WordPress user's data base.
Few times I logged-in to the forum with the admin name and naturally I could see everything including the WP dashboard because I've enabled the admin top bar for admin.
Since then, I've created few test users for different rolls and did not see the issue that you're pointing to.
I'm using 2 browsers - one for admin and the other one for test users.