• Version 3.5.2

    STEP 1. Confirm Login works

    STEP 2. Log out

    STEP 3. Click here to reset

    STEP 4. Enter Username

    STEP 5. Click Reset Password

    Message:
    Password successfully reset!

    An email containing a new password has been sent to the email address on file for your account.

    NOTE: No password is actually sent. This message should say what now??

    STEP 6. Click link with reset-password/?a=set_password_from_key&key=qoz6pEMzRuZPPWVROrXY&login=ChrisTestUser

    STEP 7. New Password shows hidden in top field asking to confirm new password but since I don't know what it is, I enter a new password into each field and click Update Password

    Seems to accept it and tells me to login.

    STEP 8. Cannot log in, says password is incorrect.

    Error: The password you entered for the username ChrisTestUser is incorrect. Lost your password?

    NOTE: Old password still works to it was not reset.

    The page I need help with: [log in to see the link]

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author Chad Butler

    (@cbutlerjr)

    The password reset request does not change the password – it initiates a process the user needs to complete (i.e. confirmation link via email) to change their password. This was introduced quite a few years ago (as emailing passwords is insecure). It began in 3.3.0 as an option, was shifted to the primary process in 3.4.0, although the legacy process would still work. The legacy process is completely obsolete as of 3.5.0.

    If you have a setup that originated prior to 3.4.0 and never changed to the new process, that would be the reason for the confusion. I’ve done the best that I can to make sure this was announced through the plugin’s release notes and change log, but I do realize most people never read those things.

    Here’s what you need to know: https://rocketgeek.com/plugins/wp-members/docs/faqs/how-to-upgrade-the-password-reset-from-legacy-versions/

    Short explanation: all you really need to do is change the content of the email so that it makes sense to the user what their next steps are. Something as simple as the following would cover it (as the process will automatically include the password reset confirmation link at the end of the message):

    A password reset was requested for [blogname]. If you did not request a password reset, simply ignore this message and the reset key will expire.

    Thread Starter EnvisionDesign

    (@envisiondesign)

    I have a password reset page with  [wpmem_form password] on it.

    When I click the link in the email and enter my password twice it DOES NOT update the password and leaves the old password in place.

    Thread Starter EnvisionDesign

    (@envisiondesign)

    Bump. Would love to have the ability to actually set a new password.

    Any thoughts?

    Thread Starter EnvisionDesign

    (@envisiondesign)

    I just ran the lastest update, but the behavior is the same.

    Logged out.

    Click Lost your password

    Entered username

    Got the link to reset (https://tacomagardenclub.org/reset-password/?a=set_password_from_key&key=hwzSvA891PoHPNgcxkM7&login=ChrisTestUser)

    Reset my Password (it appeared to accept the change)

    Cannot log in with the new password

    Old password still works (it does not appear to be updating the database with the new password)

    Thread Starter EnvisionDesign

    (@envisiondesign)

    New Info. I WAS able to reset my password AFTER I logged in and used the Password Reset in my profile.

    BUT, when I tried again via the “send password reset link” it fails.

    It seems to take my password, but is not updating the database as the new PWD never works, but my old one does.

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Password Reset Problems’ is closed to new replies.