Bug | Brute Force Feature Allows Processing of WP “Get New Password” Form
-
Good Day!
Wordfence has a Brute Force feature (or setting) called “Don’t let WordPress reveal valid users in login errors.”
When activated, the feature allows WordPress’ “Get New Password” form to process even though the “Username or Email Address” field is blank.
Is this the normal, expected behavior when the above-noted WF feature is activated?
Details:
https://ibb.co/fHq52Tj
https://ibb.co/TtTHWcyWith no backend (email) warning from Wordfence when this happens, we went crazy (and spent a lot of time) trying to figure out why the WordPress form was processing as usual and not giving us an error message when the field was blank.
Strong Recommendation:
(1) If the Brute Force feature is activated, send an email to the site administrator when someone clicks “Get New Password” button and the “Username or Email Address” field is blank.
OR
(2) Adjust your Brute Force feature code to block the form from processing while displaying on the frontend a unique error message generated by Wordfence.
Thank you!
- The topic ‘Bug | Brute Force Feature Allows Processing of WP “Get New Password” Form’ is closed to new replies.