Home User profile
tagDiv Member
This user did not write anything. So we are just showing here some random text to make the profile page look nice :)
RAINA
tagDiv Member

Hi team,

I’ve been reporting this issue since October 7, 2025 at 9:23 PM, and even after several recent updates, many users can still register by bypassing the CAPTCHA and other security measures. This leaves the door open to spammers, which is a real concern.

Could you please prioritize fixing it? I’ll hold off on the next update until it’s resolved. When it’s addressed, kindly update this thread to let us know—much appreciated!

Thanks so much, and have a great day!

RAINA
tagDiv Member

HI
Version 12.7.4 – January 14th, 2026

will fix the problem above?

RAINA
tagDiv Member

so i will not updtae last Version 12.7.3

RAINA
tagDiv Member

did you fix the issue in Version 12.7.3 – October 22nd, 2025 ??

RAINA
tagDiv Member

@bdp While they fix you can comment the line 1080 in /wp-content/plugins/td-composer/legacy/common/wp_booster/td_ajax.php

I understand the problem and the file associated with this plugin:
https://wordpress.org/plugins/notification-for-telegram/

It is a free tool to receive Telegram messages about real-time events happening on a WordPress site. There is also an option for Backtrace that captures the origin of every new user registration. The system now includes the file name and line number from which the registration was triggered, providing full traceability for debugging and security audits. This information is sent whenever a new user registers.

Have nice day
Rah

RAINA
tagDiv Member

I use cloudflare as recaptcha i dont want to use google…
the problem that ajax end point is exposed .. for me its a bug you can force to use google recapchta ….

RAINA
tagDiv Member

I re-comment the line 1080 in /wp-content/plugins/td-composer/legacy/common/wp_booster/td_ajax.php

and no more fake users

RAINA
tagDiv Member

HI
I have no Opt-In Builder active or enabled

RAINA
tagDiv Member

Hello, I updated to the latest version, 12.7.2, hoping that you had fixed the issue with fake user registrations in td_ajax.php.
I had patched the file myself to avoid the problem… but after the update, it started happening again.

Haven’t you included the fix I reported? That’s not very professional — this is a serious security issue and it should be addressed.

RAINA
tagDiv Member

THX
It has happened before… then it was resolved for a while, and now the problem has reappeared.
hope you will release a fix … So far I have commented all the requests that create users in the jQuery

  • This reply was modified 10 months by RAINA.
RAINA
tagDiv Member

the fake users comes /wp-content/plugins/td-composer/legacy/common/wp_booster/td_ajax.php around line 1080

I backtraced teh registration call

RAINA
tagDiv Member

I fixed the problem, but i want to know if you have fixed in the last update…
or we need to wait another update !

RAINA
tagDiv Member

Hi boss !!
DO Version: 12.6 fix the JS/Agent.RAW problem or still vulnerable?

  • This reply was modified 2 years by RAINA.
Viewing 13 posts - 1 through 13 (of 13 total)