But seriously though… While it may be a difficult task to guess a user’s email to sneak in there, it isn’t impossible. Especially say you’re a mod at a vaping forum, with access to all the registered user’s email addresses. You could just blast your way in, if you felt like it. This is a Security 101 blunder bigtime.
The original site had a lot of users, it was a big site for aspire UK, I used to use it a lot, this day and age they could have mass emailed all individuals quite easily requesting a password reset, this happened in 2017…