MainWP allows new user registrations and plugin installations
-
I noticed that yesterday three of my sites using the MainWP plugin sent notifications of new user registrations, despite the fact that new user registrations were disabled! Also all of the new users were administrators. Usernames and emails were as follows:
Username: mainwp-child-id-tC1p
E-mail: [email protected]
Username: mainwp-child-id-raFh
E-mail: [email protected]
Username: mainwp-child-id-63wn
E-mail: [email protected]
Username: mainwp-child-id-TUkl
E-mail: [email protected]
Username: mainwp-child-id-VWL3
E-mail: [email protected]When I discovered this today I deleted these users and tried to update the MainWP Child plugin from version 2.0.27 to version 2.0.28. via auto-update but found it impossible as the version number stayed the same. Then I deactivated the MainWP Child plugin and tried to delete it. I was surprised to find the following message:
You are about to remove the following plugins:
MainWP Child by MainWP
Vendi Abandoned Plugin Check by Vendi Advertising (Chris Haas)
Vendi Abandoned Plugin Check by Vendi Advertising (Chris Haas)I don’t know if the “Vendi Abandoned Plugin Check” is a normal part of the MainWP child plugin but I discovered that another plugin was installed on all three sites: “WordPress admin security” by Edward Caissie.
Another funny thing is that when I tried to replicate this behaviour and get the message about the “Vendi Abandoned Plugin Check” again, I noticed that even after deleting the MainWP Child plugin version 2.0.27. and installing it fresh from the WordPress Plugin Installer I get the old version 2.0.27 again instead of the new one (2.0.28).
Also there are a couple of php files in the WordPress folders that shouldn’t be there like press.php in /wp-content/plugins
- The topic ‘MainWP allows new user registrations and plugin installations’ is closed to new replies.