Strict Standards: Redefining already defined constructor for class bbdb in /home/themes/public_html/forums/bb-includes/db-mysql.php on line 12

Strict Standards: Declaration of BB_Walker_Blank::start_lvl() should be compatible with BB_Walker::start_lvl($output) in /home/themes/public_html/forums/bb-includes/classes.php on line 1127

Strict Standards: Declaration of BB_Walker_Blank::end_lvl() should be compatible with BB_Walker::end_lvl($output) in /home/themes/public_html/forums/bb-includes/classes.php on line 1127

Strict Standards: Declaration of BB_Walker_Blank::start_el() should be compatible with BB_Walker::start_el($output) in /home/themes/public_html/forums/bb-includes/classes.php on line 1127

Strict Standards: Declaration of BB_Walker_Blank::end_el() should be compatible with BB_Walker::end_el($output) in /home/themes/public_html/forums/bb-includes/classes.php on line 1127
Security Threat added by Thematic to author « ThemeShaper Forums

ThemeShaper Forums » Thematic

[closed]

Security Threat added by Thematic to author

(1 post)
  • Started 4 years ago by wprunner
  • This topic is not resolved
  1. wprunner
    Member

    Hi,

    When an Author/Admin comments on a post, Thematic puts the author username in the class of the comment.

    For example, if the user is "admin" , a class is added to his comment as "comment-author-admin".

    Many users change the name of the WordPress Admin user name from the default to something that is not easy for others to guess or crack. This adds a layer of security. Unfortunately, Thematic reveals this username in comments classes. So for example, if someone changed it to "secretadmin" the class will show as comment-author-secretadmin.

    I didn't see this in the class TwentyTen theme, only with Thematic.

    Please fix this security problem.

    Thanks.

    Posted 4 years ago #

RSS feed for this topic

Topic Closed

This topic has been closed to new replies.


Strict Standards: call_user_func_array() expects parameter 1 to be a valid callback, non-static method GA_Filter::spool_analytics() should not be called statically in /home/themes/public_html/forums/bb-includes/wp-functions.php on line 586

Strict Standards: Non-static method GA_Filter::spool_this() should not be called statically in /home/themes/public_html/forums/my-plugins/googleanalytics.php on line 183