• Dear Dev team,

    I just installed your plugin and it seems working well if I need to switch to another user.

    But I see that It has a serious sercurity issue.

    After log-out, I back to login page backend with used previous. I can access my admin account, our user and password seems saved without my permission.

    Please see image attached : https://prnt.sc/ccTGtUlDdLif

    I think that it is absolutely serious issue with admin account.

    I temporarily have to disabled it to wait your updated

    Thanks and Regards

Viewing 1 replies (of 1 total)
  • Plugin Author John Blackbourn

    (@johnbillion)

    WordPress Core Developer

    Thanks for the report.

    Did you click “Switch Off” or “Log Out”? They do two different things.

    If you click “Switch off”, it’s intended that you can immediately back to your admin account without entering your username and password. Take a look through the FAQ for some more info about this feature.

    If you click “Log Out” then you’ll be logged out fully, this message will not appear, and you will not be able to switch back again.

Viewing 1 replies (of 1 total)

The topic ‘Serious security Issue’ is closed to new replies.