WordPress.org

Make WordPress Core

Opened 16 months ago

Last modified 10 months ago

#20140 accepted feature request

Ask old password to change user password

Reported by: nprasath002 Owned by: tman4506
Priority: normal Milestone: Awaiting Review
Component: Security Version:
Severity: normal Keywords: has-patch dev-feedback
Cc: sbutze@…

Description

I have experienced this in various sites and i think
it adds extra security.
We must ask for the old password when the user tries to change the password

Attachments (1)

20140.diff (3.7 KB) - added by bootsz 10 months ago.
Adds "Current Password" field to the profile & user-edit pages.

Download all attachments as: .zip

Change History (7)

comment:1 tman450611 months ago

  • Owner set to tman4506
  • Status changed from new to reviewing

comment:2 tman450611 months ago

  • Component changed from Administration to Security

comment:3 in reply to: ↑ description tman450611 months ago

Replying to nprasath002:

I have experienced this in various sites and i think
it adds extra security.
We must ask for the old password when the user tries to change the

I I think it's a great idea. I'll work on it no guarantees though

comment:4 tman450611 months ago

  • Status changed from reviewing to accepted

comment:6 bootsz10 months ago

  • Cc sbutze@… added
  • Keywords has-patch dev-feedback added

bootsz10 months ago

Adds "Current Password" field to the profile & user-edit pages.

Note: See TracTickets for help on using tickets.