Make WordPress Core

#56732 closed defect (bug) (reported-upstream)

Log out doesn't log out, or more precisely, log out doesn't "forget" you

Reported by: asheroto's profile asheroto Owned by:
Milestone: Priority: normal
Severity: normal Version:
Component: Login and Registration Keywords:
Focuses: Cc:

Description

Hello! Did you guys know that when you log out of gravatar it doesn't actually forget the session? If you click log out, it takes you to the homepage of Gravatar, but if you click Sign In, you're still signed in. I think it's because WordPress remembers you when you log in. It shouldn't remember you anymore when you log out, because that creates a security vulnerability. Someone at my computer could just click "Log In" and wouldn't have to provide the password, even if I "logged out". 😊 If I need to contact another support team let me know, thank you!

Change History (1)

#1 @desrosj
22 months ago

  • Component changed from Security to Login and Registration
  • Keywords needs-dev-note removed
  • Milestone Awaiting Review deleted
  • Resolution set to reported-upstream
  • Status changed from new to closed
  • Version trunk deleted

Hi @asheroto,

Welcome to Trac! Even though Gravatars are supported in WordPress, the open source project has nothing to do with Gravatar's development.

Please reach out through the contact page on their website.

Note: See TracTickets for help on using tickets.