Security Flaw with Registration
-
Hi,
It seems like no matter what I’m doing in the Ultimate Member settings, I can’t seem to prevent a user from signing up with a bogus email and logging into the system (it gets re-directed to the profile page after signing up).
I tried to force the user to click on an email activation link in order to login, but to my knowledge, the only option in settings that addresses this is in Settings->Email->Account Activation Email (gear icon)->Account Activation Email checked.
So my questions are…
1) How do I prevent the automatic re-direction to the profile page after signing up?
2) How can I force the user to click on the email activation link to do first time log-in? The way it is right now, this doesn’t seem like a mandatory step even though the email gets sent, because he gets re-directed to the profile page as if he’s logged in (without needing this link).
3) Is it possible to force unverified users to have Subscriber Role but verified and logged in users to have Author role?Is there something I’m missing?
The page I need help with: [log in to see the link]
- The topic ‘Security Flaw with Registration’ is closed to new replies.