Routine WordPress Bug Fix Uncovers 919 Paid Videos Exposed to Public
A fitness membership platform's support ticket about paying members being blocked from videos led a developer to discover a far larger security flaw. While investigating the access issue on a WordPress and WooCommerce stack, the developer found that all 919 paid videos were freely accessible to anyone with a link, logged in or not. The so-called paywall was merely a static text notice displayed above a video player that loaded unconditionally for every visitor. The flaw stemmed from WishList Member's content protection being applied to a parent page, but failing to cascade to AIOVG videos stored as a separate custom post type outside WordPress's standard hierarchy. The incident prompted a full rebuild of the platform's access layer and highlighted the importance of always testing the inverse of a reported bug symptom.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in