Is this serious? Hidden controls allow to upgrade membership levels
I just found out that the user profile page provides hidden controls which can be very easily activated in the browser. When activated, these controls allow users to modify their membership level or extend one's membership without spending a penny and without the admin's knowledege.
Hiding controls is not enough. They should not be provided to the end user at all.
IMHO, this is a serious matter. I cannot understand how one can build an elaborate commercial system with paid subscription options and at the same time, allow for this kind of backdoor.
I am expecting a quick action on this one. I am sure your developers know which controls I am talking about.