{"id":1466,"date":"2018-04-25T20:03:15","date_gmt":"2018-04-25T20:03:15","guid":{"rendered":"https:\/\/jdthomson.com\/?p=1466"},"modified":"2022-07-11T10:17:44","modified_gmt":"2022-07-11T10:17:44","slug":"leaving-wordpress-files-exposed","status":"publish","type":"post","link":"https:\/\/jdthomson.com\/leaving-wordpress-files-exposed\/","title":{"rendered":"Are you Leaving your WordPress Files Exposed?"},"content":{"rendered":"
\n

Are you using WordPress, there may be an issue you don\u2019t know anything about that\u2019s affecting the security of your uploaded files. Just because you have it set up so that only people who can access have to go through an opt-in process, it doesn\u2019t always mean that the public can\u2019t access them.<\/p>\n

Lets check if you have this issue.<\/h2>\n

go to your site\u2019s upload directory.
\nFor example,<\/p>\n

WWW.yoursite.com\/wp-content\/uploads. \r\n<\/code><\/pre>\n

You may see your themes and plugins, numerous folders and lots of images. Take a closer look, and you will be able to see that file you uploaded as part of your product that you are selling.<\/p>\n

What this means that anyone with a little bit of knowledge can easily access and download any or all of your files for free.<\/p>\n

It\u2019s not hard.<\/p>\n

If you test this directory URL on other WordPress sites that you knew. Some had their upload directory are hidden, but others may not.<\/p>\n

How To Hide a WordPress Upload Directory?<\/h2>\n

There are two methods you can use.<\/p>\n

Plugin<\/h3>\n

Using Security Plugins can make it easy to restrict WordPress directory browsing so that no one can view your the uploads file.<\/p>\n

The two plugins I Recommend are:<\/p>\n