dmchale / disable-json-api

Public repo for the "Disable REST API" WordPress plugin, currently with 90,000+ active installs in the wordpress.org repository
10 stars 9 forks source link

Unintended routes accessible when plugin is enabled #26

Closed dmchale closed 3 years ago

dmchale commented 6 years ago

From https://wordpress.org/support/topic/bug-the-data-is-publicly-accessible/

amielucha (@amielucha) Plugin works for the default rest_route but using a modified route exposes all data.

This renders the plugin broken as the data is still exposed.

The page I need help with: http://www.binarytemplar.com/?rest_route=//