The MU forums have moved to WordPress.org

Allow users to upload their own theme (3 posts)

  1. eminemjamesuk
    Member
    Posted 17 years ago #

    Is there anything out there that allows users to upload their own themes and use them?

  2. nexia
    Member
    Posted 17 years ago #

    it is not suggested for some reasons...

    blog owners can be malicious and try to hack your system by adding any kind of PHP code in any template file...

    example:

    i can easily grab the content of the file wp-config.php and display it online, and by that, being able to access the mySQL server and pirate everything you have...

    i can also easily add a rewrite process in a template that will give me complete access to the wp-admin section...

    the best thing to suggest is for the system owner, to offer free/nonfree installation of themes... so you can then verify the files and be sure they are not hacks,..

  3. eminemjamesuk
    Member
    Posted 17 years ago #

    Ahh I didn't realize it was so dangerous. Thanks for the heads up! I'll probably scan then and modify them if needs be prior to allowing users to use the themes.

About this Topic

  • Started 17 years ago by eminemjamesuk
  • Latest reply from eminemjamesuk