security - Spam Registrations

Since the past 3 days, I am seeing that every day a new user registers to my WordPress site. The default role is admin a

Since the past 3 days, I am seeing that every day a new user registers to my WordPress site. The default role is admin and it's very concerning. Their email ids are [email protected] and [email protected].

I have started using Wordfence and disabled Anyone Can Register in Settings > General.

Can you suggest me what additional shall I do?

Right now, I am manually deleting registrations.

Since the past 3 days, I am seeing that every day a new user registers to my WordPress site. The default role is admin and it's very concerning. Their email ids are [email protected] and [email protected].

I have started using Wordfence and disabled Anyone Can Register in Settings > General.

Can you suggest me what additional shall I do?

Right now, I am manually deleting registrations.

Share Improve this question asked Jun 16, 2019 at 2:28 Vaibhav SharanVaibhav Sharan 1 1
  • Hi Vaibhav! We don't cover security questions in this community. I recommend you talk with a WordPress security expert asap. This is not normal behavior for a WordPress site. – MikeNGarrett Commented Jun 16, 2019 at 22:12
Add a comment  | 

1 Answer 1

Reset to default 0

I suspect that there is malware files on your system that is allowing those user registrations. There are lots of googles/bings/ducks on how to clean a hacked system. (I use my own procedure here.)

What I would do is these things:

  • change all credentials everywhere (hosting, FTP, admin etc)
  • create a new admin user with a very secure password, log in as it (to verify it works), then demote the current admin user(s) to lowest level. Especially if your admin user is called 'admin'.
  • disable xmlrpc.prg on your site (that can be a hack intrusion point)
  • reinstall WP (use the Update on the dashboard).
  • reinstall all theme from good sources via FTP. Do the same for all plugins
  • Manually look at all files in all folders on your site for 'bad' files. Sorting by date helps, since you updated everything - all updated files should have the same datestamp, so unwanted files will stick out. Don't forget to look at all hidden files, including htaccess.
  • look at generated source code of pages to ensure nothing funky in there

The site can be cleaned (I've done it, which is how I developed my procedure). But IMHO there is a strong possibility of malware code on your site allowing those registrations.

发布者:admin,转转请注明出处:http://www.yc00.com/questions/1745398337a4625983.html

相关推荐

  • security - Spam Registrations

    Since the past 3 days, I am seeing that every day a new user registers to my WordPress site. The default role is admin a

    4小时前
    10

发表回复

评论列表(0条)

  • 暂无评论

联系我们

400-800-8888

在线咨询: QQ交谈

邮件:admin@example.com

工作时间:周一至周五,9:30-18:30,节假日休息

关注微信