Ok, just so I am not misunderstanding this; @radiok you are stating that this vulnerability has nothing to do with your plugin and exists on a vanilla WP registration page? If this is so, shouldn’t this be addressed/fixed within WP itself?
I’m not trying to dispute what you’re saying, I just want to make sure I am not misreading/misinterpreting this issue.
Also, the sites which report this vulnerability in RPR say that it can be remedied by editing the source to properly sanitize the user input. Has anyone investigated and/or done this yet?
I hope this can be resolved as this plugin is fantastic and has served me very well.
Thanks!