Possible security issue?
Hi Guys,
When viewing the “about” page of any AnsPress user i’ve noticed in the address bar that the users “username” is displayed rather than “display name publicly as”. This worries me a little because it exposes a users login name. Is there any easy way this can be changed so the link includes the name the user wishes displayed rather than their username?
Thanks
Hello,
It is already displayed by WordPress in many place. Even many plugin shows username. So, I think there is nothing to worry about it.
WordPress has several such security holes.
Try this one on your site:
www.yourwebsite.com/?author=1
and you will see the name (replace the number to 2,3,4,5,6 and see all the usernames). AND #1 is ALWAYS the Admin. Go figure.
It would if my website wasn’t configured to display a “forbidden” error if that was tried, yes I agree
Thanks Rahul