[wp-trac] [WordPress Trac] #36055: Filter xmlrpc_enabled only	partly works
    WordPress Trac 
    noreply at wordpress.org
       
    Thu Mar  3 09:56:02 UTC 2016
    
    
  
#36055: Filter xmlrpc_enabled only partly works
--------------------------+------------------------------
 Reporter:  markoheijnen  |       Owner:
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  XML-RPC       |     Version:  2.9
 Severity:  normal        |  Resolution:
 Keywords:  has-patch     |     Focuses:
--------------------------+------------------------------
Comment (by mensmaximus):
 The patch is working. Methods without login needs are now disabled if the
 filter is set to true. Still one can use the system capabilities (e.g.
 system.multicall). Although you cant query any method you can put some
 nice workload on a server because it is answering the request with a error
 message. Imho if I dont need xmlrpc and want to disable it there is no
 reason to expose it at all.
--
Ticket URL: <https://core.trac.wordpress.org/ticket/36055#comment:2>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform
    
    
More information about the wp-trac
mailing list