• Plans & Pricing
  • Log in
  • Get started
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress 
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Get started
  • Sign up
  • Log in
About
  • Plans & Pricing
Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress  
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Jetpack App
  • Learn more
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Search
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Forums / SECURITY BREACH! Please help! Random unknown commenter linked to my dashboard!

SECURITY BREACH! Please help! Random unknown commenter linked to my dashboard!

  • Unknown's avatar
    alisonanddon · Member · Sep 4, 2024 at 2:06 am
    • Copy link Copy link
    • Add topic to favorites Add topic to favorites

    A commenter called Blogg Ranger posted on the site linked below on August 18th.

    I am…

    Scroll down to find his comment. Click on his name. It will take you straight to my dashboard! Complete access to my dashboard!

    I discovered this about 5 days ago and contacted the “Happiness Engineers” who have not yet responded.

    Please get this fixed.

    The blog I need help with is: (visible only to logged in users)

  • Unknown's avatar
    alisonanddon · Member · Sep 4, 2024 at 2:07 am
    • Copy link Copy link

    You will find the comment by Blogg Ranger by first clicking on Older Comments and then scrolling down.

  • Unknown's avatar
    alisonanddon · Member · Sep 4, 2024 at 3:19 am
    • Copy link Copy link

    This only happens when I’m logged in.

    It doesn’t happen on my husband’s computer, only on my computer. Of course I do not know what happens on Blogg Ranger’s computer. I DO know that even on my own computer no comment ever should link to my dashboard.

  • Unknown's avatar
    justjennifer · Member · Sep 4, 2024 at 5:38 am
    • Copy link Copy link

    Hi there, The link in that commenter’s username is to “wordpress.com”.

    This only happens when I’m logged in.

    And that’s the reason. When you are logged in to your WordPress.com account, clicking a link to wordpress.com will bring you to your own site’s dashboard (or your Sites dashboard if you have more than one site).

    Anyone else clicking that same link would be brought to their own site’s dashboard if they are logged in to their WordPress.com account. If they are not logged in to WordPress.com, they’ll land on the WordPress.com landing page. You can try that by logging out and clicking the link to wordpress.com in my forum reply.

    Hope that helps ease your mind but do let us know if you have any other concern about this.

  • Unknown's avatar
    alisonanddon · Member · Sep 4, 2024 at 6:12 am
    • Copy link Copy link

    Thank you, that does help. So you’re saying that anyone clicking on his comment on the above linked blog would be taken to their own site, if they have one, or to the landing page if they don’t have one.

    I’ve been very puzzled, and a bit stressed by this as I’ve been blogging for 10 years and have never seen anything like this before.

    So you’re saying it’s safe for me to approve and respond to his comment on my blog, and the same will happen on my blog – anyone clicking on his comment will be taken to their own blog or to the landing page.

    Thank you so much for your help

  • Unknown's avatar
    justjennifer · Member · Sep 4, 2024 at 8:14 am
    • Copy link Copy link

    anyone clicking on his comment

    The comment itself doesn’t have any link in it, however the link is in his username (Blogg etc.)

    So you’re saying it’s safe for me to approve and respond to his comment on my blog, and the same will happen on my blog – anyone clicking on his comment will be taken to their own blog or to the landing page.

    If someone has added the address “wordpress.com” on the “Public web address” line of their WordPress.com account profile, it will behave this same way for anyone clicking on their username.

  • Unknown's avatar
    justjennifer · Member · Sep 4, 2024 at 8:24 am
    • Copy link Copy link

    Also, keep in mind that a “legitimate” link in a person’s username doesn’t necessarily mean there isn’t a questionable link in the comment they leave, and vice versa.

    Here’s more information on that https://akismet.com/support/general/spam-facts/

  • Unknown's avatar
    alisonanddon · Member · Sep 4, 2024 at 3:38 pm
    • Copy link Copy link

    Thank you so much. This has been very helpful.

    Sorry I didn’t express myself well. Of course I was referring to the link in the user name, not the comment itself.

    I always look into a new commenter before approving, and I’ve never seen it before that the link in their user name took me to my own dashboard so I freaked out, and panicked that this commenter somehow had access to it, and that anyone clicking on his username had access to it. Phew!

    So I think it’s all resolved now. I appreciate your help, and for clarifying the situation.

  • The topic ‘SECURITY BREACH! Please help! Random unknown commenter linked to my dashboard!’ is closed to new replies.

Tags

  • account

About this topic

  • In: Support
  • 2 participants
  • 7 replies
  • Last activity 1 year
  • Latest reply from alisonanddon

Couldn't find what you needed?

Contact us

Contact us

Get answers from our AI assistant, with access to 24/7 expert human support on paid plans.

Browse our guides

Browse our guides

Find step-by-step solutions to common questions in our comprehensive guides.

WordPress.com

Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Professional Email
  • Website Design Services
  • WordPress Studio
  • Enterprise WordPress
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • WordPress.com Blog
  • Business Name Generator
  • Logo Maker
  • WordPress.com Reader
  • Accessibility
  • Remove Subscriptions
Help
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
  • Developer Resources
Company
  • About
  • Press
  • Terms of Service
  • Privacy Policy
  • Do Not Sell or Share My Personal Information
  • Privacy Notice for California Users
DeutschEspañolFrançaisBahasa IndonesiaItalianoNederlandsPortuguês do BrasilSvenskaTürkçeРусскийالعربيةעִבְרִית日本語한국어简体中文繁體中文English

Mobile Apps

  • Download on the App Store
  • Get it on Google Play

Social Media

  • WordPress.com on Facebook
  • WordPress.com on X (Twitter)
  • WordPress.com on Instagram
  • WordPress.com on YouTube

Automattic

Automattic
Work With Us
    • WordPress.com Forums
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • Manage subscriptions