Viewing 7 replies - 1 through 7 (of 7 total)
  • Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    I cannot reproduce that on a clean (no plugins, twentytwenty theme) WP site.

    How are you able to see users when logged in as an editor?

    Thread Starter assembleer

    (@assembleer)

    In the user section of the wp-admin.
    The users have the role editor.
    When making a test user with this role I can logon with that user and delete an admin user.

    Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    Do you have any user-related plugins or have you customized the editor role? When I’m logged in as an editor, I cannot see/edit other users.

    Thread Starter assembleer

    (@assembleer)

    I just tested with a local install.
    I also was not able to do this there.
    Not even the menu users was available now to me.
    It feels like the official site is might corrupted and that this is not a normal bug. Might being hacked?

    Is there any other place in WordPress or the installation where a role or user can elevate its rights?

    Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    There are plugins that can do that. It’s possible it was hacked. Have you scanned with a plugin like WordFence?

    Reset capabilities to defaults using https://www.ads-software.com/plugins/reset-roles-and-capabilities/

    Thread Starter assembleer

    (@assembleer)

    What we’ve noticed is that when coming from search in google. the site (first time calling it from search results) opens a advertisement (jippykajee, I seem to have won an iPhone ?? )

    So it seems the website is infected with the search engine hack I’ve read somewhere about. And that does not surprise me as I noticed the website was way back on security patches.

    I will try your suggestion and update this topic asap. thanks.thanks so far.

    Thread Starter assembleer

    (@assembleer)

    Activated the https://www.ads-software.com/plugins/reset-roles-and-capabilities/ plugin which resetted roles and rights. The situation now seems as should be expected. Thanks very much for your help.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘user with role editor can delete or edit admin accounts’ is closed to new replies.