A trick to post comments without approval by using admin username and email
|Reported by:||shanyar||Owned by:||Shanyar Kadir|
|Component:||Comments||Keywords:||comments with no moderation|
I have a word-press website, and I noticed that if some one posted a comment with my admin user-name and email, their comment will be approved without moderation ... it appears as if I have posted the comment ... of course no body of the posters have tried this, it was found by one of our admins ... I tried it my self and thought it was a theme bug ... but no ... it wasn't ... if someone finds out my email and uses my user-name he can post without my permission ... I am sure I am not imagining this ... and I didn't find a bug like this reported so I believe it is a bug ... if I have made a mistake please correct me ... I am running a self-hosted word-press website of wordpress 2.8.5 ...