BUG - Hidden controls allow to upgrade membership levels ?
Just tested this theory in cp 3.2beta2 using
wp 3.4.2
I set up a paid membership pack like so:
|
test1 |
test1 |
Free |
$50.00 / 90 days |
October 30, 2012 9:56 am by adl1 |
Active |
I then went to edit profile page and disabled inline css styles using firefox web developer.
I then checked the membership pack id in
wp back end and then went and added the id of the membership pack to the now un-hidden control field.
I then updated the profile.
This is what happened from having no membership pack to having one - all from the front end user profile page and a simple css hack:
Account Information
- adl1
- Member Since: September 12, 2012 6:10 pm
- Last Login: October 30, 2012 9:38 am
- Membership Pack: test1
- Membership Expires: December 29, 2012 9:39 am
- Renew or Extend Your Membership Pack
So If I have done this correctly - this serious issue is still with us.
FYI also
I have tested this with cp 3.1.9 /3.1.8 and the problem is exactly the same.
Not exactly heartwarming information to be honest - thankfully I haven't rolled out a live site yet !
Regards
Bleem