• Resolved Spencer Hill

    (@s3w47m88)


    Can anyone tell me how to prevent SPAM registrations? I’ve tried numerous CAPTCHA Plugins but it seems there is a vulnerability in WordPress that doesn’t apply the CAPTCHA to some hidden page that bots are finding.

Viewing 7 replies - 1 through 7 (of 7 total)
  • Andrew Nevins

    (@anevins)

    WCLDN 2018 Contributor | Volunteer support

    Wouldn’t it seem there’s a weakness with CAPTCHA?

    Thread Starter Spencer Hill

    (@s3w47m88)

    I can understand why you raise the question but the issue at hand is that WordPress is not adequately preventing SPAM registrations.

    Although I would expect a CAPTCHA Plugin to resolve the issue, which they do in the case of front end facing forms. However the issue persists which suggests to me that WordPress has a hidden mechanism to allow registrations that any of the popular CAPTCHA Plugins seem to be able to prevent.

    Andrew Nevins

    (@anevins)

    WCLDN 2018 Contributor | Volunteer support

    Thread Starter Spencer Hill

    (@s3w47m88)

    Okay, I gave this a couple weeks to see if it really did help after installing the Plugins it recommended and yes it did! Thank you!

    Thread Starter Spencer Hill

    (@s3w47m88)

    Sadly, this apparently did not resolve the issue. :/ It seemed to discourage some spam registration, slightly, but not entirely.

    I’ve literally tried every Plugin I could find, I’ve had my server scanned for malware, and I’ve pruned absolutely everything possible and the only thing that makes a difference is whether or not “Anyone can register” is selected.

    Thread Starter Spencer Hill

    (@s3w47m88)

    Is there no one else experiencing this? It seems like there is a clear exploit of WordPress registration going on.

    Thread Starter Spencer Hill

    (@s3w47m88)

    Update: I’ve disabled ALL Plugins, replaced ALL core WP files and I STILL get spam registrations. After disabling all Plugins the only thing that has worked is blocking registration completely using the option in Settings. Which is a non-solution.

    When I had other Plugins installed (WooCommerce, BBPress, BuddyPress) the normal registration pages were re-directed to /registration.

    Someone PLEASE help me with this. I can’t figure out what’s going on here and everything is saying vulnerability with WP.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Can't prevent SPAM user registration, need help…’ is closed to new replies.