guest posting if guest knows some users email address this can be problem

This topic contains 6 reply and 2 voices, and was last updated by Sekander Badsha 9 years, 8 months ago
Viewing 6 Posts - 1 through 6 (of 6 total)
Author Posts
July 17, 2014 at 7:21 am 23684
Sekander Badsha Hi About guest posting: "If a user already exists with the same e-mail address, the post will assign to that existing user." So if guest knows other users email adress guest can post anything and post will assign to that existing user . So guest can publish some bad posts. And if the form is on auto publish state this will be big problem . I think this should be disabled by some way. Something like; there should be error message like: "The email you are trying to post is exists. If you are e member plese login. Or try a different email address." Can we do this with any costom code , action , modification ? Thanks.
July 19, 2014 at 1:24 pm 23774
Sekander Badsha Sekander Badsha

Hello Brk,
Have you tested such issue ? I guess not.
If you set the guest post form default to pending, guest post will not be published right away. It will stay pending in the Admin Dashboard. And the account management thing is completely done and controlled by WordPress itself. So it won’t let you use same mail to another user/guest.

July 21, 2014 at 4:15 am 23831
Brk Brk

No i haven’t tested such issue. Because i dont want to have a shy at this 🙂

Sekander, Imagine that you are a member of my site . And someone knows your email adress. And someone publishes some bad spam posts..

Even i take guest post form default to pending, if you login to your dashboard, before site admin , you will see alot of pending spam posts in your dasboard. And i think you dont like this. May be you think there is some security problems on my site. Because someone publish posts with your account. This will be a problem.

So in my opinion email field must be checking user emails in guest posting, if that email exists or not.
If exists not publish. If not exists auto register and publish post will be okay.

Thanks.

July 21, 2014 at 8:36 pm 23885
Sekander Badsha Sekander Badsha

We have tested such and can assure you, and that won’t happen. For the peace of your own mind you should test too. No guest can use a registered mail.

July 22, 2014 at 8:34 pm 23976
Brk Brk

Ok Sekander.

Lets test together.

Here is the link that any one can post as a guest

http://t8.webxgo.info/?page_id=26

And please use email adress as: sekander@wedevs.com

This email is your registered member email in my users list.

Anyone can post for testing.

July 24, 2014 at 6:32 pm 24074
Sekander Badsha Sekander Badsha

Sorry for Misunderstanding.
I the thing you were assuming is right guest post and registered users post with the same email gets combined. I have notified the developer team about this issue and will get a fix next week (as we’re going on a vacation from tomorrow).

Thanks for finding such a complicated and important issue.

August 4, 2014 at 12:16 pm 24479
Sekander Badsha Sekander Badsha

I have talked to the developer team. They said this feature is intended to work this way. So according to them, its not a bug.
But you can post the solution (ask for a feature) in our feature request forum. I’ll forward that to the developer team and they may add that to the later updates.

Viewing 6 Posts - 1 through 6 (of 6 total)