[wp-trac] [WordPress Trac] #56732: Log out doesn't log out, or more precisely, log out doesn't "forget" you

WordPress Trac noreply at wordpress.org
Tue Oct 4 16:52:30 UTC 2022


#56732: Log out doesn't log out, or more precisely, log out doesn't "forget" you
--------------------------+-----------------------------
 Reporter:  asheroto      |      Owner:  (none)
     Type:  defect (bug)  |     Status:  new
 Priority:  normal        |  Milestone:  Awaiting Review
Component:  Security      |    Version:  trunk
 Severity:  normal        |   Keywords:  needs-dev-note
  Focuses:                |
--------------------------+-----------------------------
 Hello! Did you guys know that when you log out of gravatar it doesn't
 actually forget the session? If you click log out, it takes you to the
 homepage of Gravatar, but if you click Sign In, you're still signed in. I
 think it's because WordPress remembers you when you log in. It shouldn't
 remember you anymore when you log out, because that creates a security
 vulnerability. Someone at my computer could just click "Log In" and
 wouldn't have to provide the password, even if I "logged out". 😊 If I
 need to contact another support team let me know, thank you!

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/56732>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list