Possible security vulnerability or code injection in td_ajax.php

Posted in: Newspaper
Post count: 89

This is insane. The user has reported a security vulnerability or code injection in td_ajax.php more than 4 months ago and your only answer is that “I made a new notice to our developers; unfortunately, this is all I can do.” REALLY? Calin, REALLY?

Post count: 35449

Hi E K,
I think there’s been a bit of a misunderstanding here, so let me clarify the situation in simple terms.
This is not a code injection vulnerability in td_ajax.php. What the user reported is a case where fake users were being created, and they noticed that the registration process uses code from a specific line in a theme file. Up to this point, I believe everything is clear.
In the discussion, I explained that the theme already includes protection against fake registrations through Google reCAPTCHA, which can be enabled from the theme panel. This option was added specifically to protect the login and registration functionality from the theme. However, the user mentioned that they are using Cloudflare CAPTCHA instead and do not want to use Google reCAPTCHA. Because of this choice, the built-in theme solution cannot be applied in their case. The workaround they chose was to comment out a line of code, which stops the registration popup from creating new user accounts. This works for them, but it also changes how that functionality behaves (for example, if login is required for comments or if the popup is used elsewhere on the site).
So the situation is not that there is no solution, there is a solution, but it’s not the one the user wants to use. When someone chooses a different CAPTCHA system, a different approach is needed.
What I did was:
– clearly explain the existing solution provided by the theme
– acknowledge the user’s setup and limitations
– notify the developers that offering an alternative option could help other users in the same situation
From my perspective, this was handled correctly. If my straightforward writing style caused any confusion or gave the wrong impression, that certainly wasn’t my intention.
Thank you for your understanding!

Viewing 2 posts - 26 through 27 (of 27 total)
You must be logged in to reply to this topic.