[wp-trac] [WordPress Trac] #58410: global disable login and password reset / recovery

WordPress Trac noreply at wordpress.org
Wed May 31 04:40:15 UTC 2023


#58410: global disable login and password reset / recovery
------------------------------------+----------------------
 Reporter:  cederom                 |       Owner:  (none)
     Type:  enhancement             |      Status:  closed
 Priority:  normal                  |   Milestone:
Component:  Login and Registration  |     Version:
 Severity:  normal                  |  Resolution:  wontfix
 Keywords:                          |     Focuses:
------------------------------------+----------------------

Comment (by cederom):

 Okay, I will try the plugin.. or better modify the hooks myself by hand..
 for some reason these attacks seems to bruteforce something (there are
 tens or even hundreds each day) or targeting plugins bugs.

 The safest choice would be to have core option to disable these
 functionalities without compromising installation integrity with manual
 modifications that also may be detected as malicious (not to mention
 possible auto-update interference).

 At this time only maintenance mode seems reasonable solution and putting
 whole site down. I think this option would come handy in corner cases for
 aware users (even if available only via mysql table edit).

 Thank you for your time and response.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/58410#comment:3>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list