[wp-trac] [WordPress Trac] #57394: wp_insert_user allows the new user to have a username equal to an already registered email

WordPress Trac noreply at wordpress.org
Tue Jan 17 15:07:27 UTC 2023


#57394: wp_insert_user allows the new user to have a username equal to an already
registered email
------------------------------------+------------------------------
 Reporter:  buutqn                  |       Owner:  (none)
     Type:  defect (bug)            |      Status:  new
 Priority:  normal                  |   Milestone:  Awaiting Review
Component:  Login and Registration  |     Version:  6.1.1
 Severity:  normal                  |  Resolution:
 Keywords:  has-patch               |     Focuses:
------------------------------------+------------------------------

Comment (by roytanck):

 A possible privacy concern could be that this would allow a bad actor to
 try entering email addresses until it hits the new error message (assuming
 an open registration form). They would then know that that address is in
 use.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/57394#comment:4>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list