• I am using the basic Wordfence plugin on bell-computing.com. I had wp notification of a new user being created and a new site. Nothing from Wordfence. I immediately changed my password and WF should have 2fa from ips other than my own fixed one. Its just happened again. I have blocked the ips and deleted the users. Why didn’t WF stop this and what do I do now?

    • This topic was modified 7 years, 10 months ago by patbell101.
Viewing 3 replies - 1 through 3 (of 3 total)
  • Hi patbell101,
    I think you have WordPress Network enabled (Multisite), if so then on the main network dashboard page please check (Settings > Network Settings => Registration Settings), maybe you are choosing “Both sites and user accounts can be registered.” there?

    Thanks.

    Thread Starter patbell101

    (@patbell101)

    Good call. Though I am concerned how they logged in since I didn’t get my usual notification of an admin login and I have a very strong password. Ideally I’d like to allow dashboard login ONLY from my own fixed IP with perhap 2 factor login or an extra url parameter. Is that possible in Wordfence?

    No need to log in a website with the configuration I mentioned in my previous reply, anyone can go to example.com/wp-signup.php to create a new site/user registration and this new user role will be an admin only on this newly created website, not the whole Network. (admin user on the whole Network is called Super Admin in WordPress multisite installation).

    In Wordfence premium version “Two-factor authentication” is supported, knowing that we aren’t allowed to discuss/support premium features of the plugin here in the forums, for any further question you can always contact Presales team.

    P.S. You can make use of these two options “Whitelisted IP addresses that bypass all rules” and “Immediately block IP’s that access these URLs” to allow login from your IP only.

    Thanks.

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Unauthorised user and site created’ is closed to new replies.