I assume before you allow an email address change, you send an email to the current email address to verify the change and also an email to the new email address to verify the address.
You other thing, you have perfectly easy way to verify the account owner is making a change. Ask them to sign a message that contains a random token you generate for them with their BTC private key of the address they have on file. If they can do that, it's 99 % sure they have they are the owner of the PB minning address/acct.
so, with the above in place in order for someone to change my PMMinning email address they would have to ....
1. Hack my email account.
2. Hack my BTC wallet.
you could even make it more secure by using 2FA. This adds:
3. Have stolen my cell phone.
But, I agree, not allowing an email address change is a bit draconian.