Auto Accepted Fake Account

I had a new applicant yesterday and when I entered the software to Accept or Deny I found 2 accounts that were Auto Accepted without my consent and missing required information. I SS’s but deleted the accounts right away. The SS are linked here:

3 Responses to Auto Accepted Fake Account

  1. George December 14, 2023 at 12:01 pm #

    Then why don’t you have a security audit on your site, including all elements and addons, and if anything weird relates to Affiliates plugin, please let me know.
    The first and most important measure you should always keep in mind, is to keep your site and addons up-to-date and maintain a healthy status without issues. This way you can avoid already known vulnerabilities and issues that have been fixed but you are not aware of.

    Kind regards,

  2. Kenneth Steele December 11, 2023 at 9:46 pm #

    Well, that’s kinda my point. I have 2 Admin accounts for this site and the rest are Customers. Both of my accounts have passwords changed any time I feel they are compromised. I am 110% positive this was NOT approved by me… thus, creating this ticket.
    What else can be going on here?

  3. George December 9, 2023 at 1:08 pm #

    Hi Kenneth,

    The only way to accept new affiliate registrations that are pending, is through the Dashboard under Affiliates > Manage Affiliates, as you demonstrate on your screenshots.
    I would recommend you to review your administrative accounts once more, revoke administrative access from those that don’t need it and perhaps reset the passwords of privileged user accounts. Furthermore, have a look at Affiliates > Settings > General tab, in case you have assigned additional permissions for Affiliates management, to user roles other than the administrative role.

    Kind regards,

We use cookies to optimize your experience on our site and assume you're OK with that if you stay.
OK, hide this message.

Affiliates · Contact · Jobs · Terms & Conditions · Privacy Policy · Documentation · Downloads · Useful Plugins · My Account