我正在使用Filter Custom Fields & Taxonomies Light. 我发现它正在使用admin-ajax.php
在前端进行的AJAX搜索甚至没有登录。
请参见:
https://plugins.svn.wordpress.org/filter-custom-fields-taxonomies-light/trunk/profi-search-filter.php
add_action( \'wp_head\', \'sf_head\', 1 );
function sf_head(){
$settings = get_option( \'search-filter-settings\' );
if( !isset( $settings[\'style\'] ) || $settings[\'style\'] == \'\' )
wp_register_style( \'sf-style\', SF_URL . \'res/style.css\' );
else
wp_register_style( \'sf-style\', SF_URL . \'res/\' . $settings[\'style\'] . \'.css\');
wp_enqueue_style( \'sf-style\' );
wp_enqueue_script(\'jquery\');
wp_enqueue_script(\'jquery-ui-slider\');
wp_register_script( \'sf-script\', SF_URL . \'res/sf.js\' );
wp_enqueue_script( \'sf-script\' );
?>
<script>var sf_ajax_root = \'<?php echo admin_url(\'admin-ajax.php\'); ?>\'</script>
<?php
}
这是在Wordpress中使用AJAX的常见方法还是安全漏洞?