WPIntell

Source evidence

Email Change Vulnerability in Double Opt-in Workflow

Newsletter – Send awesome emails from WordPress · support · 2026-06-03T05:44:00+00:00

mixedsentiment
highseverity
0.83relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 36 rows with source links

16.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

30 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
capg1436 resolved
Earlier Situation (Single Opt-in): With Single Opt-in enabled, subscriptions are confirmed immediately without verification. The system allows direct email updates via the nm=profile attribute, meaning an attacker could modify a subscriber’s email or unsubscribe users simply by knowing their email address. This creates a significant vulnerability due to weak authentication in the subscription workflow. Later Situation (Double Opt-in): With Double Opt-in enabled, a confirmation email is sent when a user subscribes, improving security during initial registration. However, a flaw still exists during email updates: When a subscriber updates their email address, a confirmation email is sent to the new email ID. After confirmation, the system does not properly validate or enforce the update. As a result, even after the new email owner confirms, the email address in the system remains unchanged. The page I need help with: [ log in to see the link] Hello @capg1436 , I’ll close this one as it is a duplicate of https://wordpress.org/support/topic/email-change-vulnerability-in-double-opt-in-workflow/ . Michael

Comments

1 shown
Michael Travan 2026-06-05T07:30:00+00:00

Hello @capg1436 , I’ll close this one as it is a duplicate of https://wordpress.org/support/topic/email-change-vulnerability-in-double-opt-in-workflow/ . Michael