With the new implementation of the key registration for most of the forum, email validation was removed. The danger with this, is that if you signed up after that happened with an email that doesn't exist, you're in serious danger of having your password taken.
The exploit comes from registering the non-existent email and sending a forgotten password request, which gives you the user's password. If you have registered with an email that doesn't exist solely for the purpose of signing up faster, It's highly advised you set it to an email that you own, so that
this doesn't happen.
Also Jimmg is an starfish.
Jimmg-proof your accounts now, to stay safe.