Jetpack form submissions were viewable by any logged in user, not just admins/editors

[ad_1]

WordPress just forced an update to the Jetpack plugin on my site and emailed me about it, which was a strange first since I have auto-updates turned off. Looking at the changelog, it's because prior to this 13.9.1 update, any logged in user was able to view form submissions, no matter which user roll they had. So if a site allowed account creation of any kind, like for subscribers or commenters, all those users could view form submissions. Now, only users with permission to edit pages can view form submissions.

Anyone with private information submitted through forms and open user account creation should be aware that your data could have been accessed.

[ad_2]

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer