Skip to main content
Ejecuta cualquier Skill en Manus
con un clic

wp-password-protected-exposure

Estrellas54
Forks52
Actualizado12 de mayo de 2026 a las 11:15

Audit and fix WordPress / WooCommerce plugins that leak password-protected post content through AJAX handlers or listing-widget queries. Catches the specific gap that `is_visible()` + `post_status === 'publish'` checks miss: password-protected posts keep `post_status='publish'`, so they bypass draft/private guards while their full content (title, price, SKU, description, permalink) is rendered to unauthenticated visitors. Use when a report mentions "password-protected product/post leak", "quickview exposure", "post_password not enforced", or whenever reviewing a `wp_ajax_nopriv_` endpoint that loads a single post's content, or any widget that builds a new `WP_Query` for a public listing.

Instalación

Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.

SKILL.md
readonly