I had this plugin activated and manually activated a friends account with administrator account. It automatically logged me out of admin account and into his account. Not sure if this can be used to hack into profiles or be exploited by other users, but I thought I would mention it.
Hi Christopher,
Thank you for posting.
It is not an exploit as it will never escalate the rights of the user but still it is a bad user experience. I will have an update today. We shomehow missed this in our test and I apologize for that.Thank you
BrajeshOh, it’s all good. I just thought I would let you know 🙂
Thank you. I appreciate you reporting the issue.
Have just fixed it. Please upgrade to 1.0.3 from herehttps://buddydev.com/plugins/bp-autologin-on-activation/
Please do let me know if that works for you or not?
Thank you
BrajeshWorks good as far as I can tell. Good work 😀
Hi Christopher,
Thank you.Marking it as resolved now.
The topic ‘ [Resolved] Maybe an exploit in Autologin after activation’ is closed to new replies.