PriMoThemes — now s2Member® (official notice)

This is now a very OLD forum system. It's in READ-ONLY mode.
All community interaction now occurs at WP Sharks™. See: new forums @ WP Sharks™

paypal checkout manipulation

s2Member Plugin. A Membership plugin for WordPress®.

paypal checkout manipulation

Postby workit » October 18th, 2011, 6:55 am

hey guys,

i was testing s2member plugin and found the following problem:

1. generate a button code (for example: one time access, 20 dollar charge)
2. insert the shortcode on the website
3. when you now open the website and view the source code you will find the price for the product in the line
Code: Select all
<input type="hidden" name="amount" value="20">

4. you can now manipulate the amount value to 1 or any other amount ...
5. press the button
6. paypal will open with the amount you entered
7. proceed and s2member will accept that payment .....

ok i guess nobody with a sane mind would do this with his paypal account ... but is there any possibility to deny payments with wrong amounts? the should be some counterechecks by s2member
User avatar
workit
Registered User
Registered User
 
Posts: 2
Joined: October 18, 2011

Re: paypal checkout manipulation

Postby Eduan » October 18th, 2011, 7:34 am

You could try to have PayPal encrypt your buttons: WP Admin -> s2Member -> PayPal Options -> Account Details -> Enable Button Encryption.

Hope this helps. :)
P.S. Remember to report back. ;)
Now officially accepting Professional s2Member installations along with Bruce C (a.k.a. Ace).

If you're interested in a Professional s2Member Installation, or a Custom Coding Job, you can send your request here.
User avatar
Eduan
Experienced User
Experienced User
 
Posts: 1154
Joined: August 27, 2011
Location: Taxco de Alarcón, Guerrero, México.

Re: paypal checkout manipulation

Postby workit » October 18th, 2011, 7:58 am

Thanx for that hint, encryption works perfectly! should better be the default setting.

the only disadvantage is that shortcodes don't work it you like to sell something by external pages or in a multipress setup.
User avatar
workit
Registered User
Registered User
 
Posts: 2
Joined: October 18, 2011

Re: paypal checkout manipulation

Postby Eduan » October 18th, 2011, 8:09 am

Great, glad to be able to help. :)
Anything else you need just ask. ;)
Now officially accepting Professional s2Member installations along with Bruce C (a.k.a. Ace).

If you're interested in a Professional s2Member Installation, or a Custom Coding Job, you can send your request here.
User avatar
Eduan
Experienced User
Experienced User
 
Posts: 1154
Joined: August 27, 2011
Location: Taxco de Alarcón, Guerrero, México.


Return to s2Member Plugin

Who is online

Users browsing this forum: Exabot [Bot], Google [Bot] and 1 guest

cron