[wp-trac] [WordPress Trac] #20140: Ask old password to change user password

WordPress Trac noreply at wordpress.org
Fri Aug 16 03:00:38 UTC 2013


#20140: Ask old password to change user password
------------------------------------+-----------------------
 Reporter:  nprasath002             |       Owner:
     Type:  feature request         |      Status:  assigned
 Priority:  normal                  |   Milestone:  3.7
Component:  Security                |     Version:
 Severity:  normal                  |  Resolution:
 Keywords:  has-patch dev-feedback  |
------------------------------------+-----------------------

Comment (by DrewAPicture):

 Replying to [comment:10 iandunn]:
 > 20140.2.diff refreshes the original patch, and allows admins to change
 other users' passwords without having to know what the current one is.

 Shouldn't we check whether that user can be edited but the current user
 rather than saying only administrators can change a user's password?

--
Ticket URL: <http://core.trac.wordpress.org/ticket/20140#comment:12>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list