[wp-trac] [WordPress Trac] #47718: Verification of new admin email address can be bypassed via options.php

WordPress Trac noreply at wordpress.org
Wed Jul 17 10:00:26 UTC 2019


#47718: Verification of new admin email address can be bypassed via options.php
--------------------------------+------------------------------
 Reporter:  pixolin             |       Owner:  (none)
     Type:  defect (bug)        |      Status:  new
 Priority:  normal              |   Milestone:  Awaiting Review
Component:  Options, Meta APIs  |     Version:
 Severity:  normal              |  Resolution:
 Keywords:                      |     Focuses:
--------------------------------+------------------------------

Comment (by zodiac1978):

 I think both options (`wp-admin/options.php` and WP CLI) are not very
 known by beginners and just used by pro users - therefore the missing
 verification process is not a bug, but a feature IMHO.

 Maybe `wp-admin/options.php` should get a warning sign, like the
 plugin/theme editor. Something like "You can break things here - do you
 really know what you are doing?".

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/47718#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list