WPIntell

Source evidence

[NSFW] Session Mixed

Persistent Login · support · 2024-10-26T18:06:00+00:00

mixedsentiment
highseverity
0.95relevance
9replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

8 / 34 rows with source links

23.5% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
amfahadsafi resolved
I’m using a plugin called “WordPress Persistent Login.” However, I’m experiencing a critical issue where user sessions seem to overlap. Despite multiple tests, reinstalling, and even uninstalling the plugin, users are still encountering the following problem: When a standard user logs in with their username and password, they are sometimes mistakenly logged in with admin privileges, accessing the admin session instead of their own. Could you help identify what might be causing this, or suggest any fixes to prevent session data from mixing between users? ( when i uninstalled the plugin the issue disappear) This topic was modified 1 year, 7 months ago by amfahadsafi . Hi, thanks for opening a support request. you said at the start of your message that after uninstalling the plugin you still had the issue, but at the end of your message you said that the issue disappears. Can you clarify which is correct? As I mentioned in your review, Persistent Login uses a hook that WordPress provides to keep users logged in. This hook gives us the user ID to update. Can you provide me with an example of a user who has had this issue? An example of their login cookie, and also their session data from the database? The database data will be in the user_meta table, with a key of ‘session_tokens’ for the users ID. Please obscure their IP address and any other sensitive data. This reply was modified 1 year, 7 months ago by lukeseager . I have created over 100 users with the subscriber role and 3 administrators, with one designated as the super admin. When some subscribers log in, they are sometimes mistakenly logged in as the super admin. This issue occurs randomly with some users. The super admin has only one session option and requires 2FA to log in. However, when I install the WordPress Persistent Login plugin, sessions seem to get mixed up, and most users gain administrator access. When I deactivate the WordPress Persistent Login plugin, the issue disappears. However, when I reactivate it, the issue reappears. This reply was modified 1 year, 7 months ago by amfahadsafi . I have created over 100 users with the subscriber role, including User X and User Y . I also have 3 administrators, with one designated as the super admin . Expected Behavior : User X and User Y , both with the subscriber role, should only have limited access when they log in. The super admin should have higher privileges, limited to one active session at a time, and require 2FA for added security. Issue When Using Persistent Login Plugin : When I activate the WordPress Persistent Login plugin, User X and User Y sometimes randomly log in with super admin access rather than their intended subscriber-level access. This issue occurs inconsistently and doesn’t affect all subscribers every time. Even though the super admin is restricted to a single session and requires 2FA, the login sessions still appear to get mixed up. Temporary Solution : When I deactivate the WordPress Persistent Login plugin, the issue disappears, and users like User X and User Y only have subscriber-level access, as expected. However, when I reactivate the plugin, the session mix-up issue reappears. Hi thank you for the information. Can I ask if you’re website is a wordpress Multi site? You mention a super admin role, which isn’t a standard role on a single WordPress website. Is it possible to share the website URL so I can test signing up as a subscriber to replicate the issue? by mean of super admin i mean Administrator role ( the one by default) Thank you. Is your website a WordPress Multi site installation? No its not multi site Thank you for confirming. Are you able to share the URL of the website with me please? If you’re concerned about sharing the URL publicly, you can send it to luke@persistentlogin.com (if wordpress.org administrators are happy for me to request that). I’m conscious that any information shared here that lets me assist you could potentially be used to gain administrator access to your website. Which we definitely want to avoid. Hi, I’m going to close this thread as it’s been over a month without a reply. If you are still having issues, please open a new support request.

Comments

9 shown
lukeseager 2024-10-27T08:30:00+00:00

Hi, thanks for opening a support request. you said at the start of your message that after uninstalling the plugin you still had the issue, but at the end of your message you said that the issue disappears. Can you clarify which is correct? As I mentioned in your review, Persistent Login uses a hook that WordPress provides to keep users logged in. This hook gives us the user ID to update. Can you provide me with an example of a user who has had this issue? An example of their login cookie, and also their session data from the database? The database data will be in the user_meta table, with a key of ‘session_tokens’ for the users ID. Please obscure their IP address and any other sensitive data. This reply was modified 1 year, 7 months ago by lukeseager .

amfahadsafi 2024-10-30T08:18:00+00:00

I have created over 100 users with the subscriber role and 3 administrators, with one designated as the super admin. When some subscribers log in, they are sometimes mistakenly logged in as the super admin. This issue occurs randomly with some users. The super admin has only one session option and requires 2FA to log in. However, when I install the WordPress Persistent Login plugin, sessions seem to get mixed up, and most users gain administrator access. When I deactivate the WordPress Persistent Login plugin, the issue disappears. However, when I reactivate it, the issue reappears. This reply was modified 1 year, 7 months ago by amfahadsafi .

amfahadsafi 2024-10-30T09:16:00+00:00

I have created over 100 users with the subscriber role, including User X and User Y . I also have 3 administrators, with one designated as the super admin . Expected Behavior : User X and User Y , both with the subscriber role, should only have limited access when they log in. The super admin should have higher privileges, limited to one active session at a time, and require 2FA for added security. Issue When Using Persistent Login Plugin : When I activate the WordPress Persistent Login plugin, User X and User Y sometimes randomly log in with super admin access rather than their intended subscriber-level access. This issue occurs inconsistently and doesn’t affect all subscribers every time. Even though the super admin is restricted to a single session and requires 2FA, the login sessions still appear to get mixed up. Temporary Solution : When I deactivate the WordPress Persistent Login plugin, the issue disappears, and users like User X and User Y only have subscriber-level access, as expected. However, when I reactivate the plugin, the session mix-up issue reappears.

lukeseager 2024-10-30T12:08:00+00:00

Hi thank you for the information. Can I ask if you’re website is a wordpress Multi site? You mention a super admin role, which isn’t a standard role on a single WordPress website. Is it possible to share the website URL so I can test signing up as a subscriber to replicate the issue?

amfahadsafi 2024-10-30T18:06:00+00:00

by mean of super admin i mean Administrator role ( the one by default)

lukeseager 2024-10-31T06:54:00+00:00

Thank you. Is your website a WordPress Multi site installation?

amfahadsafi 2024-10-31T07:05:00+00:00

No its not multi site

lukeseager 2024-11-01T07:13:00+00:00

Thank you for confirming. Are you able to share the URL of the website with me please? If you’re concerned about sharing the URL publicly, you can send it to luke@persistentlogin.com (if wordpress.org administrators are happy for me to request that). I’m conscious that any information shared here that lets me assist you could potentially be used to gain administrator access to your website. Which we definitely want to avoid.

lukeseager 2025-01-02T07:20:00+00:00

Hi, I’m going to close this thread as it’s been over a month without a reply. If you are still having issues, please open a new support request.