Membership Plugin

WordPress Membership Plugin

  • Home
  • Documentation
  • Addons
  • Support
    • Quick Setup
    • Documentation
    • Premium Addon Support
    • Paid Support
    • Support Forum
    • Support Forum Search
    • Forum Login
    • Forum Registration
  • Contact

[Resolved] Hackers injecting members

Simple Membership Plugin › Forums › Simple Membership Plugin › Hackers injecting members

Tagged: Hackers injecting members

  • This topic has 3 replies, 2 voices, and was last updated 2 years, 3 months ago by The Assurer.
Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • July 2, 2024 at 12:48 pm #28348
    shiplofts
    Participant

    Good Day Support & community, I have version of Simple WordPress Membership installed, newest being the current release.

    Both are receiving membership injections. Seems a bot is successfully inserting a member that shows up on the Membership::Members. These stay in Activation Required mode and tend to come from different ip address and is inserted a fake / undeliverables email address. The failed message sit in the WWW- email account as bounces.

    94.103.188.103 – – [02/Jul/2024:05:23:43 -0700] “GET /registration/ HTTP/2.0” 200 54251 “” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36”
    94.103.188.103 – – [02/Jul/2024:05:23:46 -0700] “POST / HTTP/2.0” 200 98144 “https://XXXXXXXX.com/registration/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36”

    Any assistance would be appreciated as we get 10-20 of these per day.

    -D

    July 2, 2024 at 10:01 pm #28349
    The Assurer
    Moderator

    These stay in Activation Required…

    So, the default behavior of SWPM is keeping the bots at bay, but your tables are filling up wuth junk entries.

    Please take a look at this:
    These stay in Activation Required
    https://simple-membership-plugin.com/blacklisting-whitelisting-feature/

    Another idea is to require a token payment of $0.50 to register. This small amount not only covers your payment processing fee, but you will generate a token revenue stream. The $0.50 amount is the minimum you can accept with Stripe. PayPal will accept a lower amount, but you want to recover your processing fee.

    July 2, 2024 at 10:19 pm #28350
    shiplofts
    Participant

    Not only tables filing up, but also the mail system tries to sent out emails to these bogus accounts as well. These get stuck in www-mail account, which builds up as well and because of all the bad mail, lowers your mail reputation score with the large providers such as Gmail.

    Each time is a different IP & email combination, so whitelist/blacklist is not a solution.

    I wish I could charge a fee for but, but unfortunately cannot.

    If these are indeed coming from a Bot, how is it getting past Captcha v3

    There has to be a better solution to the issue.

    July 4, 2024 at 11:33 pm #28355
    The Assurer
    Moderator

    If these are indeed coming from a Bot, how is it getting past Captcha v3

    AI — Captcha v3 is over 6 years old. And that’s not all — per Wikipedia… “In October 2023, it was found that OpenAI’s GPT-4 chatbot could solve CAPTCHAs.”

    Your best strategy is to charge a $1 registration fee, good for a discount on a paid membership. That’s what I would do.

  • Author
    Posts
Viewing 4 posts - 1 through 4 (of 4 total)
  • You must be logged in to reply to this topic.
Log In

Please read this message before using our plugin.

Search

Featured Addons and Extensions

  • Membership Form Builder Addon
  • Member Directory Listing Addon
  • WooCommerce Payment Integration
  • Member Data Exporter Addon

Documentation

  • Documentation Index Page

Copyright © 2026 | Simple Membership Plugin | Privacy Policy