Skip Navigation

[Resolved] URGENT – User information has been exposed to public

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Supporter timezone: Asia/Kolkata (GMT+05:30)

This topic contains 8 replies, has 1 voice.

Last updated by Minesh 2 weeks, 4 days ago.

Assisted by: Minesh.

Author
Posts
#2855708
Screenshot 2026-04-08 170225.png

It has been brought to my attention that Ranger user profiles on our site are now visible to the general public, whereas previously they were only visible to logged-in users. This represents a serious data protection issue.

Could I please request technical support to determine what has changed?

I have recently downloaded and installed the latest version of Toolset.

I have checked the Access Control settings and shared the relevant screen below. As you can see, Guests, Subscribers, Registered Users, Contributors, and Organisers should not be able to view any Ranger posts.

I have also reviewed the following tutorial and ensured that all steps have been followed correctly:
https://toolset.com/course-lesson/restricting-access-to-pages/

I would appreciate your urgent assistance in investigating this matter and identifying the cause.

Kind regards,

#2855764

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

That is strange. What modifications you have done with your site?

What posts exactly you want to restricet? do you want to restrict any specific posts of post type or all the posts of post type?

*** Please make a FULL BACKUP of your database and website.***
I would also eventually need to request temporary access (WP-Admin and FTP) to your site. Preferably to a test site where the problem has been replicated if possible in order to be of better help and check if some configurations might need to be changed.

I have set the next reply to private which means only you and I have access to it.

#2857138

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

I see you do not shared the password with the private information.

Can you please share admin access details as well as frontend user access details to what user and few ranger profile links that shoiuld be accessible to the frontend user and admin and to what user it should be not accessible.

I have set the next reply to private which means only you and I have access to it.

#2857148

hidden link - login page
hidden link - this should be hidden to guest and only viewed by members to the hub
hidden link You should not be able to see this in a google search - currently set to private to protect the users details

#2857155

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Well - I need admin access details. If you check the screenshot you shared - it shows "password is not provided."

I also need frtonend user access details to that user the ranger post should be accessible -correct? and to whom the ranger posts should not be accessible.

I have set the next reply to private which means only you and I have access to it.

#2857177

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

When I try to login with the access details you shared with your previous reply, I can see the following error:

LOGIN BLOCKED: 2FA is required to be active on your account. Please contact the site administrator.

Can you please disable 2FA for now and send me working administrator role user access details.

I have set the next reply to private which means only you and I have access to it.

#2858115

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

I logged in as administrator user you shared: Toolset Admin 2026

But when I try to see the Ranger post type listing page in admin:
- hidden link

I do not see "View" link to view the ranger post on frontend. I'm not sure what changes you made or what plugin you installeand and revoked. It seems there is no read permission for even administrator user or you have done some customizations?

Can you give me full rights to administrator so that I can view the "View" link for the ranger post on post type lising page as well as give me one user account that I can use to login as frontend user and that user should have rights to see the rander profile.

I have set the next reply to private which means only you and I have access to it.

#2858122
Screenshot 2026-04-24 113939.png

you have full access to wordpress. the reason you can not see the ranger profiles is becuase i have made them private via the dashborad to prevent them from being searched for by the public because they are not private.

I created a test profile here - hidden link - a few weeks ago, this was exposed but I have just tested it and it seems to be protected I have just created the following ranger profile - hidden link and that is also behaving as it should

my issues it that I do not know how the profiles where exposed and am worried it will happen again. I followed Toolset tutoral on members to the letter.

Thanks

#2858130

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

For your Ranger post type, I've edit the post type:
=> hidden link

And then I've uncheck the checkbox "publicly_queryable" under the "Options" section and saved the post type. So now, the ranger post type should not be publically queryable.

Can you try to use WordPress default search from frontned and then try to search with keyword/title that is available with any of the Ranger profile post and check if you able to see ranger post.