[wp-trac] [WordPress Trac] #36055: Filter xmlrpc_enabled only partly works
WordPress Trac
noreply at wordpress.org
Thu Mar 3 09:56:02 UTC 2016
#36055: Filter xmlrpc_enabled only partly works
--------------------------+------------------------------
Reporter: markoheijnen | Owner:
Type: defect (bug) | Status: new
Priority: normal | Milestone: Awaiting Review
Component: XML-RPC | Version: 2.9
Severity: normal | Resolution:
Keywords: has-patch | Focuses:
--------------------------+------------------------------
Comment (by mensmaximus):
The patch is working. Methods without login needs are now disabled if the
filter is set to true. Still one can use the system capabilities (e.g.
system.multicall). Although you cant query any method you can put some
nice workload on a server because it is answering the request with a error
message. Imho if I dont need xmlrpc and want to disable it there is no
reason to expose it at all.
--
Ticket URL: <https://core.trac.wordpress.org/ticket/36055#comment:2>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform
More information about the wp-trac
mailing list