1
The top admin bar in the the xpressme read screen is welcoming a previous user instead of (yours truly). Even when displayed user is offline.
It has a user account edit feature associated with it that allows them to edit the profile. However the profile that it gives you to edit is your own despite who the display says you are.
There are web tutorials to stop it from being called in xpressmes functions.php, however none of them worked.
So I just neutered the admin bar by removing most of the functions from admin-bar.php, then update the module in modules admin. It has stripped all WordPress logo, about, links, forums, feedback, edit, ability for someone with read only privileges to go to the backend (dangerous), and the ability of user to tweak his profile through the WP admin bar.
While this file is actually from the WP supply chain not Xpressme, Xpressme maintainer should still block WP profile from using xpressme to change XOOPS profile.
Works nice now.