Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-12978

Access denied for self-service recurring contribution URLs in WordPress

    Details

      Description

      The self-service links for donors to update or cancel their recurring contributions contain URL paths that are not currently handled in the WordPress plugin file (WordPress/civicrm.php) civicrm_check_permissions(). This results in users getting Access Denied even though they have the corresponding CMS permission ('make online contributions').

      Need to add these 'second arguments' to the permitted CiviContribute path arguments:
      'updaterecur', 'updatebilling', 'unsubscribe'

        Attachments

          Activity

            People

            • Assignee:
              dgg David Greenberg
              Reporter:
              dgg David Greenberg
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: