• Hi,

    I was playing with user capabilities and copied the admin role to one I called Developer. I then edited the developer role and took away all user creation, deletion, and editing capabilities as well as the ability to manage capabilities. With “promote user” still intact I noticed that my “Developer” role can promote/demote my admin role down to a developer. This left me in a situation where I had no admins and the inability to access user management but luckily had a staging site to refresh everything. How can I keep someone other than an Admin from changing other admins?

    Thanks

Viewing 1 replies (of 1 total)
  • Plugin Author Kevin Behrens

    (@kevinb)

    Make sure your WP role levels (as displayed at the bottom of CME’s role editing screen) are set correctly. Administrator should be 10, all others lower.

    If that doesn’t resolve it, I will need more config details and possibly site access to pursue this, since I haven’t been able to reproduce it. CME is designed to automatically prevent this type of inappropriate change by limited user managers, and does on my test site.

Viewing 1 replies (of 1 total)

The topic ‘Promote User Problem’ is closed to new replies.