• Plans & Pricing
  • Log in
  • Get started
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress 
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Get started
  • Sign up
  • Log in
About
  • Plans & Pricing
Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • WordPress Studio
  • Enterprise WordPress  
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • Support Center
  • WordPress News
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
Jetpack App
  • Learn more
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Search
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
Forums / WordPress security failure?

WordPress security failure?

  • Unknown's avatar
    babsjeheron · Member · Apr 1, 2023 at 1:52 pm
    • Copy link Copy link
    • Add topic to favorites Add topic to favorites

    Someone subscribed me to follow their blog WITHOUT MY PERMISSION and set me up to receive emails when they post. This is a big security concern and I feel violated. The individual has admitted adding me. Why would WordPress make this possible? I have never shared my password with anyone nor have i granted anyone any access privileges to my account or blog. I am outraged and feel violated and stalked.

    WP.com: Yes
    Jetpack: No
    Correct account: Yes

    The blog I need help with is: (visible only to moderators and staff)

  • Unknown's avatar
    staartmees · Member · Apr 1, 2023 at 2:43 pm
    • Copy link Copy link

    You could start by asking yourself: how did that person get my email address? That’s were the security flaw starts.

    On the wordpress.com platform someone can add you to his mailing list, but without your consent this stays dead.

  • Unknown's avatar
    babsjeheron · Member · Apr 2, 2023 at 10:45 am
    • Copy link Copy link

    Thanks…An individual can add your email to their list but you must approve that in order to be subscribed as a follower.

    Anybody can get your email address if you have ever previously followed them or commented on their blog – email notifications for comments have included the commenter’s email addy and even IP address.

    I manually unfollowed their blog in October 2022 after having followed for a few years. They added me back as a follower in the last days of March 2023. I saw their blog pop up in my reader unannounced and was surprised.

    The individual then emailed me on March 30, 2023, and let me know that they “…recently discovered that they can add subscribers from their end.”

    HOW CAN A BLOG OWNER ADD SUBSCRIBERS FROM THEIR END AND SET UP EMAIL NOTIFICATIONS WITHOUT MY PERMISSION OR APPROVAL?

    Their blog is innocuous and my relationship with the blogger is not fraught or hostile at all. However I unfollowed for a reason and have a right to not be forced to follow any blogs without my prior approval. I have a right to not receive WP push notifications at 4:30am in my time zone. Thanks for any insight you can share.

  • Unknown's avatar
    staartmees · Member · Apr 4, 2023 at 7:29 am
    • Copy link Copy link

    You can and must manage push notifications yourself on your smartphone.

    And is I already said in a previous answer: “On the wordpress.com platform someone can add you to his mailing list, but without your consent this stays dead.”

  • Unknown's avatar
    babsjeheron · Member · Apr 4, 2023 at 8:34 am
    • Copy link Copy link

    I appreciate your feedback and yes, that’s correct that someone can add you to their mailing list and without your approval it is SUPPOSED to “stay dead” and that I can manage my push notifications.

    HOWEVER in this case, the individual added me as a follower to both their blog in my reader without any approval action on my part AND they enabled email notifications that send me an email whenever they post, again without any approval action on my part whatsoever.

    In other words, it did not “stay dead” which would be the usual expected outcome. I do not do email notifications for blog posts (except for maybe half a dozen blogs maximum and this one was never one of them).

    This situation is not a case of any user error on my part. The woman admitted in writing that they added me to follow their blog. My question is how can Person A add Person B as a follower without any approval action whatsoever on the part of person B? Thanks in advance for helping to unravel this mystery

  • The topic ‘WordPress security failure?’ is closed to new replies.

Tags

  • account
  • wpcomhelp

About this topic

  • In: Support
  • 2 participants
  • 4 replies
  • Last activity 3 years
  • Latest reply from babsjeheron

Couldn't find what you needed?

Contact us

Contact us

Get answers from our AI assistant, with access to 24/7 expert human support on paid plans.

Browse our guides

Browse our guides

Find step-by-step solutions to common questions in our comprehensive guides.

WordPress.com

Products
  • WordPress Hosting
  • WordPress for Agencies
  • Become an Affiliate
  • Domain Names
  • AI Website Builder
  • Website Builder
  • Create a Blog
  • Professional Email
  • Website Design Services
  • WordPress Studio
  • Enterprise WordPress
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • WordPress.com Blog
  • Business Name Generator
  • Logo Maker
  • WordPress.com Reader
  • Accessibility
  • Remove Subscriptions
Help
  • Support Center
  • Guides
  • Courses
  • Forums
  • Contact
  • Developer Resources
Company
  • About
  • Press
  • Terms of Service
  • Privacy Policy
  • Do Not Sell or Share My Personal Information
  • Privacy Notice for California Users
DeutschEspañolFrançaisBahasa IndonesiaItalianoNederlandsPortuguês do BrasilSvenskaTürkçeРусскийالعربيةעִבְרִית日本語한국어简体中文繁體中文English

Mobile Apps

  • Download on the App Store
  • Get it on Google Play

Social Media

  • WordPress.com on Facebook
  • WordPress.com on X (Twitter)
  • WordPress.com on Instagram
  • WordPress.com on YouTube

Automattic

Automattic
Work With Us
    • WordPress.com Forums
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • Manage subscriptions