bug potentially dangerous

  • Post count: 67
    July 22, 2016 at 7:14 am #21369

    hi guys

    something you have to fix urgently.

    either as an applicant or employer when adding text to any of the freetext boxes it allows a user to create a link via the link buttons.
    have you noticed that when clicking the link button it gives the user the option to add links to any of the internal pages such as contact page or whatever page you have created.

    I am sure that is not something you want to allow an applicant or employer to do.


    Post count: 2592
    July 25, 2016 at 1:46 am #21390

    so how if user trying to put link to their portfolio right there?

    Post count: 67
    July 25, 2016 at 5:59 am #21393


    i agree that an employer or applicant should be able to add a link into their job description or resume description.
    but what you don’t want is that an employer / applicant can see a list of all the website owner’s pages such as contact page, job list page, blog page and so on and link to them. this should only be accessible to administrators, editors and so forth.

    what is happening at the moment is that your template uses the core functionality of the create a link button within the visual editor.

    to test it login as an employer or applicant and add a link into any of your description textareas. you should see that wordpress visual editor offers you a complete list of all your created pages within your website.

    Post count: 2592
    July 27, 2016 at 1:28 am #21407

    hi huwcole, i think easiest way is to hide it by using css.
    try to add this css :

    i will try to find how wordpress add those button, hopefully i able to find it, and able to remove it programmatically.

    Thank you

    Post count: 67
    July 27, 2016 at 3:49 pm #21417

    thanks, that works very well. you should add that to your template until you find a proper solution

    Post count: 2592
    July 28, 2016 at 1:24 am #21419

    ok huwcole

You must be logged in to reply to this topic.