I just noticed that an EE site I run has a bunch of members (about 20) that should not be there. The only valid accounts are my super admin and 2 accounts for my client. These members belong to the same group as my client’s account and only one of them still has status “pending”.
The site does not feature member sign ups at all. There is one form that is a login form which posts to an external site (different domain) and a there are also a few Freeforms, nothing more than elaborate contact forms.
What is MOST worrying is that when I google their usernames, they seem to pop up on various EE powered forums. Try a google for .(JavaScript must be enabled to view this email address) for example.
One result shows: Newest Members: tomasze, handtruck, Tracy, mycheapseo, karl3war7, .(JavaScript must be enabled to view this email address), curtdill89, GetSeo, MichaelWaskl, craig5paul
I have 3 of those usernames in my list of members and several can be found across various EE forums. Signing up on a forum is not really a problem but how could these people become members on my site if there is no public signup?
EDIT: I am able to login as these members and they have the same rights as my client. NOT GOOD :(
Anyone know what’s going on?