Make WordPress Core

Opened 14 years ago

Closed 14 years ago

#11134 closed defect (bug) (duplicate)

A trick to post comments without approval by using admin username and email

Reported by: shanyar's profile shanyar Owned by: shanyar-kadir's profile Shanyar Kadir
Milestone: Priority: high
Severity: major Version: 2.8.5
Component: Comments Keywords: comments with no moderation
Focuses: Cc:


I have a word-press website, and I noticed that if some one posted a comment with my admin user-name and email, their comment will be approved without moderation ... it appears as if I have posted the comment ... of course no body of the posters have tried this, it was found by one of our admins ... I tried it my self and thought it was a theme bug ... but no ... it wasn't ... if someone finds out my email and uses my user-name he can post without my permission ... I am sure I am not imagining this ... and I didn't find a bug like this reported so I believe it is a bug ... if I have made a mistake please correct me ... I am running a self-hosted word-press website of wordpress 2.8.5 ...

Change History (1)

#1 @filosofo
14 years ago

  • Milestone Unassigned deleted
  • Resolution set to duplicate
  • Status changed from new to closed

Duplicate of #10931

Note: See TracTickets for help on using tickets.