Possible security issue?

Solved4.68K viewsIssues
0

Hi Guys,

When viewing the “about” page of any AnsPress user i’ve noticed in the address bar that the users “username” is displayed rather than “display name publicly as”. This worries me a little because it exposes a users login name. Is there any easy way this can be changed so the link includes the name the user wishes displayed rather than their username?

 

Thanks

0

Hello,

It is already displayed by WordPress in many place. Even many plugin shows username. So, I think there is nothing to worry about it.

commented on answer

Thanks Rahul

0

WordPress has several such security holes.

Try this one on your site:

www.yourwebsite.com/?author=1

and you will see the name (replace the number to 2,3,4,5,6 and see all the usernames). AND #1 is ALWAYS the Admin. Go figure.

commented on answer

It would if my website wasn’t configured to display a “forbidden” error if that was tried, yes I agree