Hi team,
I’ve been reporting this issue since October 7, 2025 at 9:23 PM, and even after several recent updates, many users can still register by bypassing the CAPTCHA and other security measures. This leaves the door open to spammers, which is a real concern.
Could you please prioritize fixing it? I’ll hold off on the next update until it’s resolved. When it’s addressed, kindly update this thread to let us know—much appreciated!
Thanks so much, and have a great day!
HI
Version 12.7.4 – January 14th, 2026
will fix the problem above?
so i will not updtae last Version 12.7.3
did you fix the issue in Version 12.7.3 – October 22nd, 2025 ??
@bdp While they fix you can comment the line 1080 in /wp-content/plugins/td-composer/legacy/common/wp_booster/td_ajax.php
I understand the problem and the file associated with this plugin:
https://wordpress.org/plugins/notification-for-telegram/
It is a free tool to receive Telegram messages about real-time events happening on a WordPress site. There is also an option for Backtrace that captures the origin of every new user registration. The system now includes the file name and line number from which the registration was triggered, providing full traceability for debugging and security audits. This information is sent whenever a new user registers.
Have nice day
Rah
I use cloudflare as recaptcha i dont want to use google…
the problem that ajax end point is exposed .. for me its a bug you can force to use google recapchta ….
I re-comment the line 1080 in /wp-content/plugins/td-composer/legacy/common/wp_booster/td_ajax.php
and no more fake users
HI
I have no Opt-In Builder active or enabled
Hello, I updated to the latest version, 12.7.2, hoping that you had fixed the issue with fake user registrations in td_ajax.php.
I had patched the file myself to avoid the problem… but after the update, it started happening again.
Haven’t you included the fix I reported? That’s not very professional — this is a serious security issue and it should be addressed.
THX
It has happened before… then it was resolved for a while, and now the problem has reappeared.
hope you will release a fix … So far I have commented all the requests that create users in the jQuery
-
This reply was modified 10 months by
RAINA.
the fake users comes /wp-content/plugins/td-composer/legacy/common/wp_booster/td_ajax.php around line 1080
I backtraced teh registration call
I fixed the problem, but i want to know if you have fixed in the last update…
or we need to wait another update !
