Looks like the Newsletter plugin is used to inject new users (vulnerability)

Posted in: Newspaper
Post count: 42

This morning, I saw multiple new users being added to the backend of my WordPress website using the Newspaper theme.

Upon investigation, I found out that the Newsletter form is the only place where new users are able to register themselves.

The default “Anyone can register” setting is unchecked in core WordPress settings. Please take care of this vulnerability.

I will turn off the Plugin for now. However, this needs to be addressed.

Thanks

Post count: 20685

Hi,

If you mean our subscription plugin, it has it’s own setting -> https://prnt.sc/DSTgj0mbWNXy Normally if a subscription plugin is used, then visitors should be able to create accounts and subscribe. For bot protection the theme recaptcha can be used -> https://prnt.sc/_nvgt73H3TFQ

Thank you!

Viewing 2 posts - 1 through 2 (of 2 total)
You must be logged in to reply to this topic.