[wp-trac] [WordPress Trac] #36055: Filter xmlrpc_enabled only partly works

WordPress Trac noreply at wordpress.org
Thu Mar 3 09:56:02 UTC 2016


#36055: Filter xmlrpc_enabled only partly works
--------------------------+------------------------------
 Reporter:  markoheijnen  |       Owner:
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  XML-RPC       |     Version:  2.9
 Severity:  normal        |  Resolution:
 Keywords:  has-patch     |     Focuses:
--------------------------+------------------------------

Comment (by mensmaximus):

 The patch is working. Methods without login needs are now disabled if the
 filter is set to true. Still one can use the system capabilities (e.g.
 system.multicall). Although you cant query any method you can put some
 nice workload on a server because it is answering the request with a error
 message. Imho if I dont need xmlrpc and want to disable it there is no
 reason to expose it at all.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/36055#comment:2>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list