[wp-trac] [WordPress Trac] #4353: Everyone above subscriber sees everyone's comments, IPs, and emails

WordPress Trac wp-trac at lists.automattic.com
Mon May 28 16:28:22 GMT 2007


#4353: Everyone above subscriber sees everyone's comments, IPs, and emails
----------------------------+-----------------------------------------------
 Reporter:  idahofallzcom   |       Owner:  anonymous                                                          
     Type:  defect          |      Status:  new                                                                
 Priority:  high            |   Milestone:  2.4                                                                
Component:  Administration  |     Version:  2.1.3                                                              
 Severity:  critical        |    Keywords:  comments edit_posts IP email privacy subscriber author role_manager
----------------------------+-----------------------------------------------
 I've been fighting this problem for several weeks now. I've updated Role
 Manager to the new one (not the owen winkler version), and it also does
 not fix the problem.

 Everyone above subscriber can click "comments" and see everyone's
 comments, email addresses, and IP addresses. This is a very BAD thing.

 From what I've read, edit_posts for contributor and authors is supposed to
 only display the person's own comments. However this function is broken
 somehow and instead anyone can see everyone else's comments.

 Is this a core code issue or a plugin issue? I think it is core code.

 This is very important for me to resolve because i've had to demote
 everyone on my blog to subscriber, and nobody is able to post anymore.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/4353>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list