[wp-trac] [WordPress Trac] #10268: Profile and Edit user pages should be secure too

WordPress Trac wp-trac at lists.automattic.com
Thu Jun 25 10:15:37 GMT 2009


#10268: Profile and Edit user pages should be secure too
-------------------------------+--------------------------------------------
 Reporter:  Denis-de-Bernardy  |       Owner:  ryan 
     Type:  defect (bug)       |      Status:  new  
 Priority:  normal             |   Milestone:  2.8.1
Component:  Security           |     Version:       
 Severity:  normal             |    Keywords:       
-------------------------------+--------------------------------------------
 With admin_ssl off, and login_ssl on, the profile page ends up insecure.
 It should at least send its POST request over SSL, since a new password
 might be set.

 And possibly use a secure form as well (see #10267).

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/10268>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list