Forum Replies Created
-
AuthorPosts
-
vborovic
ParticipantIt would also be a good idea to somehow implement a white/blacklist feature for the usernames and email addresses, which should be blocked from using during customer/subscriber registration and later account updating (i.e “admin”, “administrator”, info@domain.com, admin@domain.com etc.)
vborovic
ParticipantIt will happen during the new member registration phase (after completing a payment via the activation link that is sent by an email) and I can easily do the same via Simple WP Membership -> Add Member (when manually entering a username).
The issue is that, if I have an admin named “test” with an e-mail address test@test.com, and a member would try to register the same username (which currently does work that way), the WP plugin user will be successfully created, but also, the admin’s e-mail will be replaced with say “member@member.com”, which came from the member registration form and his user role will be changed from administrator to subscriber.
This happens with or without the “Force WP User Synchronization” option. The WordPress is a standard installation, apart from the WP Members plugin, I’m also using WooCommerce, but with no members/buyers (only for internal listings, no checkouts, purchases etc).
Forgot to add that I’m also using the “Membership Form Builder Addon”, but the described issue was happening without it as well.
vborovic
ParticipantI’ve hit this issue today by accident, luckily during site testing. Indeed, the WP Membership plugin username can be the same as one of the “original” members, and what happens then is that the master admin user (the username that was “over-ridden”) has his user level switched from Administrator to a lower level Subscriber. What follows when you try to login as an Admin, the main site blocks you out, because you don’t have the dashboard login rights (and you won’t be able to login to the plugin as well, since you don’t exist as an admin user there).
To put it simply, the WP Members plugin should also check and prevent double usernames and e-mails not only within itself, but out of the main wpip_users table, else this is a potential security risk where admins can be locked out because of user errors (or intentionally).
Please solve this issue.
-
AuthorPosts