Bug : Role change in profile form by administrator
-
I reported this bug 2 years ago and it still not resolved : “In Profile, when Admin change the role field and click the update button the update seems to be accepted and the screen come back as usual… but the role is still the old one.” Reference at discussion with @champsupertramp : https://www.ads-software.com/support/topic/bug-role-change-in-profile-form-by-administrator-2/
II do understand that you did have to fix Vulnerabilities with 2.1.12. Ref.?https://www.wordfence.com/blog/2020/11/critical-privilege-escalation-vulnerabilities-affect-100k-sites-using-ultimate-member-plugin/ but I am surprise that you still (2 year after) did not modified that “patch” in order to restore the fonctionnality of modifying role. That shoud be revisited.
This has been discussed in you github repo https://github.com/ultimatemember/ultimatemember/issues/687 and is still open.
@nikitasinelnikov mentions in that discussion that “It’s not a problem to return this ability by a hook.” Could that please be implemented asap. There would be no problem for me to use that hook as I am using Wordfence that has a rule to protect that vulnerability.
Please tell me how I should use the hook.
Thanks.
- The topic ‘Bug : Role change in profile form by administrator’ is closed to new replies.