Is this a known security bug with S2Member?
Open registration is set to "No (do NOT allow Open Registration)". However if I request a password reset from the wp-login.php page and then click on the link in the email sent by WordPress the link sends me to a page where the "Register" link shows on the page. From here I can register a new account:
http://~/wp-login.php?action=rp&key=JG1 ... zh3&login=
I don't want open registration, all users will be manually input by the sysadmin. Is there a way to fix the issue described above?