WPIntell

Source evidence

Mercado Pago Issues (WooCommerce) OAuth flow iframe/CSP issue

Adminify – White Label, Admin Menu Editor, Login Customizer · support · 2026-02-20T22:43:00+00:00

complaintsentiment
highseverity
0.82relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

2 / 22 rows with source links

9.1% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

20 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
gastonhe unresolved
Hi, I’m running a WordPress Multisite with WooCommerce and the official Mercado Pago plugin. When I try to switch / reconnect the Mercado Pago account from wp-admin, the flow fails. Adminify seems to open the MercadoLibre/MercadoPago authorization flow inside an internal Adminify “window” (it behaves like an embedded view/iframe or a wrapped navigation). MercadoLibre blocks being embedded due to CSP ( frame-ancestors 'none' ), so the screen shows “connection refused” and the process cannot continue. In the browser console I get errors like: Framing 'https://www.mercadolibre.com/' violates Content Security Policy directive: "frame-ancestors 'none'". Blocked a frame with origin 'https://<my-domain>' from accessing a cross-origin frame. Also, when I temporarily disable Adminify only for that page, after Mercado Pago redirects back to wp-admin the backend UI becomes duplicated (Adminify panel + native WP admin panel nested), which breaks the admin experience. Could you please advise: Is there a way to force external auth flows (OAuth) to open in a top-level window / new tab instead of being embedded/wrapped by Adminify? Is there a supported way to disable Adminify for a specific plugin page (Mercado Pago settings) without causing the “double admin” UI after redirects? If there’s a compatibility setting (disable ajax navigation, disable embedded views, etc.) for specific URLs, what is the recommended approach? Thanks. Hi @gastonhe I understand your problem. I am having discussing with our team and also forwarded this to our dev team for fast fixing. I will let you know the update as soon as we have a solution or update regarding your issue. Thank you

Comments

1 shown
jemeeroy 2026-02-21T04:11:00+00:00

Hi @gastonhe I understand your problem. I am having discussing with our team and also forwarded this to our dev team for fast fixing. I will let you know the update as soon as we have a solution or update regarding your issue. Thank you