Registration exploi...
 
Notifications
Clear all

Limited Support

Our team is currently on holiday, so support will be limited during this period. Response times may be slower than usual, and some inquiries may be delayed.
We appreciate your patience and understanding, and weโ€™ll resume our usual support by the end of August.

 

Registration exploit

2 Posts
2 Users
1 Reactions
370 Views
Posts: 1
Topic starter
(@alexabfm)
New Member
Joined: 3 months ago

I encountered a security issue with the registration form. A bot exploited the "Create Account" functionality and generated hundreds of fake accounts.

I had enabled the "Confirm Email" option, which requires users to set a password via a confirmation link sent to their email. However, the problem arose because the username field is appended to the end of the [site_url]. This allowed the bot to inject potentially malicious links by manipulating the username.

As a result, wpForo automatically sent confirmation emailsโ€”containing these tampered linksโ€”to hundreds of email addresses that had been submitted through the form.

1 Reply
Sofy
Posts: 5483
 Sofy
Admin
(@sofy)
Support Team
Joined: 8 years ago

Hi,

Please check out this FAQ: https://wpforo.com/community/faq/how-to-stop-spam/#post-39862

Reply