Theme builder template endpoint exposed

Posted in: Newspaper
Post count: 74

I had ChatGPT review my website for security vulnerabilities. This is what it said:

A second confirmed issue is that the site publicly exposes a theme builder template endpoint at /tdb_templates/single-post-template-uk-london-news-pro/. That page contains sample placeholder content like “Sample Post Title!” and tags such as “art”, “test”, and “wordpress,” which should not normally be useful to the public. This is an information disclosure problem: it helps attackers fingerprint your stack and theme behavior, and it tells them you are running a WordPress setup with tagDiv-style template builder pages exposed.

Does that endpoint need to be exposed? I don’t use that template.

https://www.wheredoitakethekids.com/tdb_templates/single-post-template-uk-london-news-pro/

Regards,
Kevin

Post count: 74
Post count: 35449

Hi,
Unfortunately, the cloud templates cna be used only iof those are publish (the cloud template ar some CPTs) and in order to can be used on the site to be apply those ust be publish.
Also, in case you do not want them to be indexed on Google, then this cna be done and will not affect the site with anything.
To remove the URL, you need to use Yoast SEO and choose not to index the cloud templates: https://i.imgur.com/6BRLmIs.png for Rank Math, https://imgur.com/WFyEf6W, https://imgur.com/MprNNxq. After that, you need to reindex your website on Google (or you can reindex only that link).
Thank you!

Viewing 3 posts - 1 through 3 (of 3 total)
The forum ‘Newspaper’ is closed to new topics and replies.