Registration exploi...
 
Notifications
Clear all

Registration exploit

2 Posts
2 Users
1 Reactions
302 Views
Posts: 1
Topic starter
(@alexabfm)
New Member
Joined: 2 months ago

I encountered a security issue with the registration form. A bot exploited the "Create Account" functionality and generated hundreds of fake accounts.

I had enabled the "Confirm Email" option, which requires users to set a password via a confirmation link sent to their email. However, the problem arose because the username field is appended to the end of the [site_url]. This allowed the bot to inject potentially malicious links by manipulating the username.

As a result, wpForo automatically sent confirmation emailsβ€”containing these tampered linksβ€”to hundreds of email addresses that had been submitted through the form.

1 Reply
Sofy
Posts: 5477
 Sofy
Admin
(@sofy)
Support Team
Joined: 8 years ago

Hi,

Please check out this FAQ: https://wpforo.com/community/faq/how-to-stop-spam/#post-39862

Reply