Snoop Around and Access Someone’s WordPress Dashboard Panel

While doing some testing on one of my websites that uses WordPress, I registered as a subscriber.   Later on, while still logged in as the subscriber, I typed in the URL that I would have used as the admin, forgetting that I wasn’t logged in as the admin. Surprisingly, I was still taken to the back-end dashboard of the website, although I didn’t have the same level of access or ability to make changes.

Although there isn’t much (if anything) that can be done in the Dashboard as a subscriber, there is still a treasure trove of information that can be found. A subscriber can see the publisher’s post count, comment count, spam count, recent incoming links, and possibly most importantly, the WordPress version that is running on the website.

The reason it’s important to shield others from seeing the WordPress version you are running is because many WP updates have security components due to known exploits. If someone is behind on their upgrade, a hacker may be able to do something malicious with one of the known exploits. There are other ways to find out what version of WP someone is running (footer or source code), but many people prevent the display of this info by using a special plugin or coding to have it removed.

There is a way to prevent access to your dashboard, and it’s something I implemented already (see screenshot above). Under Settings in the Dashboard, there is a link for General settings. On this page, make sure the “Anyone can Register” check box is not checked and people won’t be able to register. If you do allow people to register, make sure the default is Subscriber so they don’t have other privileges.

Even if you don’t have a link displayed for people to register, they can use the standard registration url used by all WordPress blogs and websites (just substituting your domain name). It’s not terrible if someone gains access to your Dashboard, but I don’t think it’s helpful either.

Elliot Silver
Elliot Silver
About The Author: Elliot Silver is an Internet entrepreneur and publisher of DomainInvesting.com. Elliot is also the founder and President of Top Notch Domains, LLC, a company that has closed eight figures in deals. Please read the DomainInvesting.com Terms of Use page for additional information about the publisher, website comment policy, disclosures, and conflicts of interest. Reach out to Elliot: Twitter | Facebook | LinkedIn

3 COMMENTS

  1. El-Sil,

    thanks for thinking of us and posting this. You rock. Buy a double Lagavulin Islay scotch for yourself at Domainfest, and send me the bill… 😉

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Recent Posts

ASAP.com Sold in Bankruptcy Auction

2
The ASAP.com domain name was sold in a bankruptcy auction managed by Heritage Global Partners (HGP). The sale price was $340,000, plus an additional...

GoDaddy Auctions: “Improve chances of winning this domain!”

5
I was attempting to place bid on an auction at GoDaddy Auctions this morning when I was shown this message on the bid confirmation...

Dan.com Being Retired by GoDaddy

5
GoDaddy acquired Dan.com in 2022. The company reportedly spent north of $71 million USD to acquire the domain name sales platform. This morning, GoDaddy...

My Largest Offer

4
I spend quite a bit of time trying to buy domain names. Some of the best deals I've made have come on domain names...

QW.com UDRP Denied Due to “Fraudster”

1
A UDRP was filed at the World Intellectual Property Organization (WIPO) against the valuable 2 letter QW.com domain name. The complaint was a bit...