Hello,
We are experiencing a serious bot-registration problem on our WooCommerce store running the XStore theme, and after investigation we have traced the root cause to the theme’s AJAX registration flow. We need your help to mitigate it.
What we found
We pulled all 2026 user registrations with no associated orders from the database. The volume is significant and clearly automated:
– 4,202 fake registrations over 6 weeks, starting March 18, 2026, at a steady rate of 100+ per day.
– Registrations arrive in daily blocks — for example, 135 users on 2026-04-25.
– Between April 25–27, just two IPs accounted for 367 registrations:
146.19.125.71 -> 206 registrations
146.19.125.65 -> 161 registrations
Bot request pattern (from our access logs):
GET /account/
POST /wp-admin/admin-ajax.php -> redirect
GET /account/?registered=