• When I discovered that bbpress BY DEFAULT bcc’s all of the participants of a topic in an e-mail – revealing their e-mail address when viewing the full header of a new topic modification I was shocked.

    WordPress and BBpress use bbpress use bbpress in their support forums and have made this fix for themselves – but not the CORE.

    WHYW?!? I don’t know.

    I’m just glad that this plugin was available as a quick-fix and hope that WordPress will WAKE UP about this obvious flaw and fix it for everyone.

Viewing 1 replies (of 1 total)
  • Plugin Author Markus Echterhoff

    (@mechter)

    Thanks for your rating!

    Could you elaborate on when exactly the email addresses are revealed? When sending BCCs the recipient list is not included in the header, that would only be the case for CCs, which are not used by bbPress notifications. So while there are issues with the BCC approach to subscriptions, privacy is usually not one of them.

Viewing 1 replies (of 1 total)
  • The topic ‘Corrects egregious privacy violation’ is closed to new replies.