WordPress.org

Make WordPress Core

Opened 2 years ago

Last modified 2 years ago

#41391 new defect (bug)

Links to media in password protected pages

Reported by: sdoffing Owned by:
Milestone: Awaiting Review Priority: normal
Severity: normal Version: 4.7.5
Component: Security Keywords:
Focuses: Cc:

Description

I was able to see a google search and view a pdf that was housed on a password protected page. This was one of 2 pages I found: http://www.mspcommercial.net/wp-content/uploads/2012/07/4-tessar-14.pdf. Please confirm that the other PDFs we have stored on pages that are set up the exact same way are safe.

Thank you.

Samantha Doffing

Change History (1)

#1 @TRILOS
2 years ago

Well I assume the protection of media files is generally not intended by the development. Password protected pages can even be found by a search within WP. I´d expect at least a notification like a modal alert window which gives a note (and requires confirmation) on these facts after assigning a password protection to a page.
It´s not a bug, this should be a feature request.

Note: See TracTickets for help on using tickets.