tlovett1 / custom-contact-forms

Build beautiful custom forms and manage submissions the WordPress way.
https://taylorlovett.com
161 stars 50 forks source link

API is not protected in any way #304

Closed Hrnkas closed 7 years ago

Hrnkas commented 7 years ago

I was able to get the form submissions without any kind of authentication, just by visiting the url http://www.mywebsite.com/wp-json/ccf/v1/forms/349/submissions/ I tried it using Incognito mode in Chrome and also using my cell phone browser (also a chrome).

Is there any official way to protect the api using some sort of authentication? In the meantime I have to use rather unsecure http auth.

cmmarslender commented 7 years ago

@tlovett1 I was able to confirm this as well.