Hi,
I would love to say "thanks for letting me know" to Mariete, but I cannot.
Let´s make things straight.
You mention you are a former professional in the IT. You should therefore know the rule number one when you find a vulnerability. That rule is - contact the developer privately, give them some time to fix it and then if they do nothing, publish it. This is to prevent anyone from misusing this vulnerability. You know my email because you have repeatedly contacted me in the past and you have also got a reply within hours. It is therefore very strange that you never informed me privately and directly about this and instead you publish it at several forums. Very unprofessional.
I am currently moving flat, dealing with some health issues and finishing up a project at work, I therefore did not have much time to look at this forum, which is primarily intended for users.
Second, this is not a serious vulnerability that would in any way put the user´s page at risk in terms of being hacked. It is not an ideal script and I agree it should be changed, but for someone who does not understand things you make it look as if it was a major problem and sever risk for the page as such.
What is even more concerning is that you went as far as sending emails directly to users you found. This is very strange, you email users, but never me...
Last but not least, it is disappointing to see such behavior especially from you in particular, someone who has told me about their unemployment and other issues, which prevent you from being able to donate towards covering the costs for the development and I have always been understandable about this and sent you the key for free....
I am glad you found a problem and I am glad for making a solution, but the way you went about it was very unprofessional.
This issue will be fixed in v19.