[wp-trac] [WordPress Trac] #15369: Worpress exposes clear text passwords in the UI

WordPress Trac wp-trac at lists.automattic.com
Wed Nov 10 12:34:36 UTC 2010


#15369: Worpress exposes clear text passwords in the UI
--------------------------+-------------------------------------------------
 Reporter:  nh2           |       Owner:                 
     Type:  defect (bug)  |      Status:  new            
 Priority:  lowest        |   Milestone:  Awaiting Review
Component:  Security      |     Version:                 
 Severity:  trivial       |    Keywords:  passwords      
--------------------------+-------------------------------------------------

Comment(by nacin):

 Replying to [comment:1 westi]:
 > This does nothing to actually hide the passwords.
 >
 > The fields are much more user friendly as plain text for entering.
 >
 > We could consider not displaying the email server password and returning
 a blank string and just letting people change it but the others are fine
 as they are.

 Agreed on all accounts. The mail server one is a good compromise.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/15369#comment:3>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list