[wp-trac] [WordPress Trac] #50072: Users with email addresses containing a single quote cannot reset their passwords

WordPress Trac noreply at wordpress.org
Mon May 4 09:31:19 UTC 2020


#50072: Users with email addresses containing a single quote cannot reset their
passwords
-----------------------------+------------------------------
 Reporter:  daniele.perilli  |       Owner:  (none)
     Type:  defect (bug)     |      Status:  new
 Priority:  normal           |   Milestone:  Awaiting Review
Component:  Users            |     Version:  5.4
 Severity:  major            |  Resolution:
 Keywords:                   |     Focuses:
-----------------------------+------------------------------

Comment (by daniele.perilli):

 Sorry, I inverted the values of the two variables:
 $user_email is escaped = **daniel.o\'brian at gmail.com**
 $old_user_data->user_email is not escaped = **daniel.o'brian at gmail.com**

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/50072#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list