Old thread but still very relevant since no changes have been made. I have the same problem as I need to change both e-mail (old abandoned yahoo.com e-mail) and password (compromised by another site).
Wouldn't it have just been better to offer app-based 2FA auth as a means of proving our identity? Now I can't change pass or e-mail and am too lazy to contact support about it. I no longer have any business with this site and was trying to change password out of courtesy so someone else doesn't log in and commit some malicious act.