Auto Accepted Fake Account

I had a new applicant yesterday and when I entered the software to Accept or Deny I found 2 accounts that were Auto Accepted without my consent and missing required information. I SS’s but deleted the accounts right away. The SS are linked here: https://www.dropbox.com/t/hCuBJaBERJv5e24m


Comments

3 responses to “Auto Accepted Fake Account”

  1. Then why don’t you have a security audit on your site, including all elements and addons, and if anything weird relates to Affiliates plugin, please let me know.
    The first and most important measure you should always keep in mind, is to keep your site and addons up-to-date and maintain a healthy status without issues. This way you can avoid already known vulnerabilities and issues that have been fixed but you are not aware of.

    Kind regards,
    George

  2. Kenneth Steele Avatar
    Kenneth Steele

    Well, that’s kinda my point. I have 2 Admin accounts for this site and the rest are Customers. Both of my accounts have passwords changed any time I feel they are compromised. I am 110% positive this was NOT approved by me… thus, creating this ticket.
    What else can be going on here?

  3. Hi Kenneth,

    The only way to accept new affiliate registrations that are pending, is through the Dashboard under Affiliates > Manage Affiliates, as you demonstrate on your screenshots.
    I would recommend you to review your administrative accounts once more, revoke administrative access from those that don’t need it and perhaps reset the passwords of privileged user accounts. Furthermore, have a look at Affiliates > Settings > General tab, in case you have assigned additional permissions for Affiliates management, to user roles other than the administrative role.

    Kind regards,
    George

Share