Profile Builder Pro is sending user passwords in email – clear text!!
-
Hello,
Profile Builder Pro is sending emails to users with their passwords in them.
After a user resets their password on our site, they get an email notice with their password in it!
REALLY?
That is massively unsecured and a HUGELY bad practice.
This MUST be fixed immediately!
Our site has over 100,000 members and we cannot afford this to keep happening.
Imagaine all the Profile Builder Pro users who have sites sending passwords in email to users!!!!!
Tonight I’m backing up our site and DB, and editing this line of code:
$recoveruserMailMessage2 = sprintf( __( 'You have successfully reset your password to: %1$s', 'profile-builder' ), $new_pass ); set $new_pass to just ''
That’s line 280 of wp-content/plugins/profile-builder/front-end/recover.php
I hope Profile Builder Pro will step up and fix this massive security error in the plugin.
Chris
- The topic ‘Profile Builder Pro is sending user passwords in email – clear text!!’ is closed to new replies.