WordPress.org

Make WordPress Core

Opened 12 years ago

Closed 12 years ago

Last modified 4 weeks ago

#7673 closed defect (bug) (invalid)

why add global groups in wp?

Reported by: tmcookies Owned by:
Milestone: Priority: high
Severity: major Version:
Component: Security Keywords:
Focuses: Cc:

Description

wp-settings.php adds the following global groups to the cache object: users, userlogins and usermeta. This means, that all the userlogins are saved at the same spot for different wp-installations on one server resulting in a leakage. I think this setting only makes sense in wpmu, but not in normal wp, since user data isn't global across multiple wp-installations.

Change History (3)

#1 @ryan
12 years ago

  • Milestone 2.6.2 deleted
  • Resolution set to invalid
  • Status changed from new to closed

Many people share their user tables in WP and require global groups. Nothing is saved in the same spot for different wp-installations unless specially configured to do so.

This ticket was mentioned in Slack in #core-editor by youknowriad. View the logs.


20 months ago

This ticket was mentioned in Slack in #core-editor by nrqsnchz. View the logs.


4 weeks ago

Note: See TracTickets for help on using tickets.