A common requirement of clients is the need for a user to enter their existing password before they can change their password.
This is a common feature in CMS systems and it would be great to see it incorporated in the next release of WordPress.
Without this facility, I am forced to use other CMS systems (eg. Joomla!) that do offer this protection.