Skip to main content

PSA about giving admin access to support or special roles

David Scurlock, thankfully informed me of a gaping security hole in my staging site security, and I am thankful to him for finding the security oversight, and taking the time to inform me of it. His post about this issue was evidently deleted, so this post is to close the loop for anyone who saw that.

You can see the problem described and the solution I came up with to solve it here in my community, if that is something you are interested in.

TL;DR don't enable the manage_options capability for beta testers or other custom roles when giving access to your wp admin. Use my instructions and snippet instead 😁

arjun arjun

JeffΒ Hi jeff thanks for the info. I tried visiting your community through the link you provided. Unfortunately, the access to your site is blocked by CloudFlare.

Jeff Mapes

arjun arjunΒ sorry, I will double check on the blocks, but they are there to block only a few places. where are you from?

arjun arjun

JeffΒ m from Nepal.

AndrΓ© Daus

Your link leads to a private space. However, reading the tl;dr giving admin access to beta users or any other non admin is always a bad idea anyway. I am wondering if there is a security risk in the software or if it was just a wrongly given access to users.

Jeff Mapes

@andre2731Β You only have to be logged in to see it, sorry. I updated the link so you land in the community, not the locked space.