Exploitable bug with drafts!
-
Hi,
As far as I can tell, there is a bug. (or perhaps of course there is something I have misunderstood) π
I have tested this with a user I created on my site. I have journalists create posts on the front-end of my site. I have enabled the posts to become ‘pending’ when they create a post.
However when a user creates a draft (with the ‘save as draft’ enabled) and then edits the post (with ‘edit post’ enabled) The draft-post becomes automatically published, without any authorization from admins.This must be some kind of bug. Or do you know how I can surpass this issue?
Both the ‘save as draft’ and ‘edit posts’ are pretty much necessities for my journalists when creating posts for the site.
The topic ‘Exploitable bug with drafts!’ is closed to new replies.