PSA about giving admin access to support or special roles
David Scurlock, thankfully informed me of a gaping security hole in my staging site security, and I am thankful to him for finding the security oversight, and taking the time to inform me of it. His post about this issue was evidently deleted, so this post is to close the loop for anyone who saw that.
You can see the problem described and the solution I came up with to solve it here in my community, if that is something you are interested in.
TL;DR don't enable theΒ manage_options capability for beta testers or other custom roles when giving access to your wp admin. Use my instructions and snippet instead π
JeffΒ Hi jeff thanks for the info. I tried visiting your community through the link you provided. Unfortunately, the access to your site is blocked by CloudFlare.
arjun arjunΒ sorry, I will double check on the blocks, but they are there to block only a few places. where are you from?
JeffΒ m from Nepal.
Your link leads to a private space. However, reading the tl;dr giving admin access to beta users or any other non admin is always a bad idea anyway. I am wondering if there is a security risk in the software or if it was just a wrongly given access to users.
@andre2731Β You only have to be logged in to see it, sorry. I updated the link so you land in the community, not the locked space.