Big security flaw when used with bbpress
-
Hi there, I think I just discovered a pretty major security flaw in this plugin. We are running this alongside BBPress. Well one of my users just alerted me to the fact that when she views the profile of another forum user, the little “switch to” appears above the other user’s email address. She tried it and was able to post things as the other person!! (she didn’t, but she could have)
See https://awesomescreenshot.com/0952n5ric3
I think there needs to be a check in this plugin that only lets this function run for admins. I can’t imagine that this would be a feature you’d want to allow regular subscribers to play with, is it?
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
- The topic ‘Big security flaw when used with bbpress’ is closed to new replies.