- This topic has 2 replies, 2 voices, and was last updated 1 year, 8 months ago by .
Viewing 3 posts - 1 through 3 (of 3 total)
Viewing 3 posts - 1 through 3 (of 3 total)
- You must be logged in to reply to this topic.
WordPress Membership Plugin
Simple Membership Plugin › Forums › Simple Membership Plugin › Password reset link can’t be disabled
The password reset link feature doesn’t require an email confirmation — that is, if a user knows any other user’s email address, they can reset their password at any time.
This opens it up for abuse, so I tried to disable it by unchecking the “Enable Password Reset Using Link” in SWPM settings. However, it appears to have made no difference, and I was able to reset my test user’s password.
For now I’ve just deleted the shortcode from the generated password reset form page, but the login form still contains a link to it. Is there an easy way to remove this?
You have the option of emailing a reset link, that must be clicked; which is sent to the email address.
https://simple-membership-plugin.com/password-reset-notification-email-customization/
If the alleged victim does not click the link… nothing happens.
Ah, then I just totally misunderstood that option, my bad.
I will probably leave it off until there’s more activity on the site, then buy the captcha plugin and enable the reset link option.
Thanks for explaining!