Changing Email Method a Security Risk
-
As we were doing some user maintenance and changing the master email under General Settings, I realized the methodology seems flawed. Specifically, when you change the primary email address on the installation, the notice goes to the new email for approval, but not the old email.
Every other online account system we’ve used sends a notice to the outgoing address asking them to approve the change. Why is WP not doing the same? Theoretically, a soon to be former employee or contractor could change the primary account email without the true owner knowing and wreak havoc without anyone knowing.
Am I missing something?
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘Changing Email Method a Security Risk’ is closed to new replies.