S2member-o.php publically viewable?

Hey,

So I noticed some odd traffic on my site. It turns out this PHP file is publically viewable using this URL?

/wp-content/plugins/s2member/s2member-o.php?ws_plugin__s2member_js_w_globals=1

Is that normal? It displays a lot of variables about the current user and installation.

Thanks!

Please see this comment for a detailed explanation: https://github.com/websharks/s2member/issues/961#issuecomment-226339850

1 Like