[wp-trac] [WordPress Trac] #53975: Send Reset Password bulk-action/link missing for non-super admins (multi-site only)

WordPress Trac noreply at wordpress.org
Sun Aug 22 00:26:24 UTC 2021


#53975: Send Reset Password bulk-action/link missing for non-super admins (multi-
site only)
----------------------------+-----------------------------
 Reporter:  jcutler         |      Owner:  (none)
     Type:  defect (bug)    |     Status:  new
 Priority:  normal          |  Milestone:  Awaiting Review
Component:  Administration  |    Version:  5.8
 Severity:  normal          |   Keywords:
  Focuses:                  |
----------------------------+-----------------------------
 Admin users in multi-site do not have the ability to send password reset
 emails from /wp-admin/users.php.

 Repro Steps:
 On a site with multisite, create a user, assign admin role.
 Go to /wp-admin/users.php.

 Expected Results:
 Admin can send a reset password email to any user.

 Actual Results:
 Send password reset link missing from actions links
 Send password reset option missing from bulk-actions drop-down

 Other Information:
 class-wp-users.php -> get_bulk_actions() uses "if ( current_user_can(
 'edit_users' ) )" as the condition to determine if this can be allowed.
 The same check is performed in the single_row() method when the actions
 are specified.

 I understand there are restrictions in multi-site for user
 creation/editing for non-super admins, however I believe this is not a
 security action and should not be restricted for site administrators.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/53975>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list