Users with create/delete user perms can delete admin users??
-
I’ve installed PublishPress Capabilities Free into my WP site, and have built the site around three main types of users. Let’s call them:
- SiteEditor: Basically the same as a standard WP Editor, but with a different name for various reasons.
- SuperSiteEditor: The same as a SiteEditor, but with all the User capabilities turned on — add, delete, edit, etc.
- Administrator: The standard WP admin role
In this setup, SuperSiteEditors can create SiteEditors and SuperSiteEditors, but not Administrators, which makes sense. However, I’ve found that a SuperSiteEditor can delete an Administrator account, which seems REALLY wrong. That’s definitely not what I want, and I’m having trouble understanding why it would be the case. Am I confused about something, or have I screwed something up? Bottom line: Can I set up my site so SuperSiteEditors can delete SiteEditors but not Administrators (and, I guess while I’m at it, not other SuperSiteEditors)? Thanks!
- The topic ‘Users with create/delete user perms can delete admin users??’ is closed to new replies.