[wp-trac] [WordPress Trac] #44434: oEmbed start pulling in iframes from any websites

WordPress Trac noreply at wordpress.org
Fri Jun 22 08:46:13 UTC 2018


#44434: oEmbed start pulling in iframes from any websites
-------------------------------------+------------------------------
 Reporter:  drivdigital              |       Owner:  (none)
     Type:  defect (bug)             |      Status:  new
 Priority:  normal                   |   Milestone:  Awaiting Review
Component:  Embeds                   |     Version:
 Severity:  normal                   |  Resolution:
 Keywords:  reporter-feedback close  |     Focuses:
-------------------------------------+------------------------------
Changes (by swissspidy):

 * keywords:   => reporter-feedback close
 * component:  General => Embeds


Comment:

 Which sites are being embedded and where does that happen? Can you please
 share the exact URL of a site where this happens? Or at least a
 screenshot?

 > These are not websites on a list of the oEmbed providers form the codex,
 these are just regular websites.

 Since version 4.4, WordPress has oEmbed discovery activated by default.
 WordPress itself is an oEmbed provider, too. This means you can easily
 embed posts from other WordPress sites in your blog.

 To disable this behaviour, you can install a plugin like
 [https://wordpress.org/plugins/disable-embeds/ Disable Embeds]. You'll
 still be able to embed YouTube videos and the like, but not other
 WordPress sites. Also, other WordPress sites won't be able to embed your
 site.

 > I've got a privacy policy page that is now flooded with oembeds

 I don't see anything on https://www.fjellrevenshop.no
 /personvernerklaering-fjellrevenshop-no/

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/44434#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list