First i've posted this here and James Huff sugested to create a bug report.

Current situation with clean install and twenty 17 theme.

Reset password with an email address that exists in the user section
get a text message after reload that a password reset link was send to the given address

Reset password with an email address that doesn’t exist in the user section
get a redirect to the password reset page… nothing else

According to general standards like this, or this I would expect the same response like:

If you have an account with us we’ve send you an email with a link to reset your password.


If WP cares less about security/privacy at least I would expect a text to display with a failed password request. Especially now we know there IS a difference between an existing and non existing email address.

UX Bug
At least we could state that we now have a situation where we do inform the customer and where we leave them in great doubt if anything happened at all. This can’t be good for the users of the sites that work with WP.

#1 @pratikgandhi
6 years ago

Hello @yuluma

Thank you for the question. I have tested it in the WordPress latest version and I got the error message that ERROR: There is no user registered with that email address. in lost password page. can you please give more clarity by giving the screenshot?


#2 @ocean90
6 years ago

#3 @yuluma
6 years ago

Thanx @pratikgandhi and @ocean90 for testing. No clue why this happened because when I test today I cannot reproduce.


#4 @SergeyBiryukov
6 years ago

No worries @yuluma, thanks for the follow-up! :)

