Stop unwanted WordPress registrations by identifying the route that creates the accounts, then applying controls to that route. Turning off one general setting may not disable a membership plugin or WooCommerce account form. Do not delete users in bulk until you know whether they own orders or content.
First distinguish account spam from a possible compromise. Unexpected administrator privileges, unexplained role changes or unauthorized content deserve an incident investigation. A burst of ordinary subscriber accounts alone does not establish how attackers entered or whether they obtained privileged access.
Inventory public account entry points
List the native registration page, store account page, checkout account creation, membership forms and any integration that creates users. For each, record whether public registration is necessary and which role a successful signup should receive.
The General settings documentation covers WordPress's native membership setting. Plugin-managed registration can have independent controls. Ask the business owner before closing a route that customers use to access purchases or subscriptions.
Inspect a small sample of unwanted accounts
Record creation times, roles and the relevant route from available logs. Redact email addresses before sharing examples. Compare an authorized test signup with one suspicious record; do not infer origin solely from a strange username or email domain.
Review the roles and capabilities model when deciding the minimum access required. An ordinary public registration should not unexpectedly gain site-management capabilities. If it does, preserve evidence and investigate configuration and extension versions before allowing more accounts.
Unexpected privileges: Preserve evidence and investigate the route. Ordinary account spam: Apply route-specific abuse controls. Existing customers: Verify login, purchases and access remain intact. Cleanup: Check ownership of orders and content first. Original explanatory guide, not a customer test result.
Apply controls without breaking checkout
Disable registration only on unused routes. On required routes, use the extension's supported verification, rate limiting or anti-abuse integration. Keep an accessible alternative for legitimate visitors who cannot complete a challenge. Test the actual account-creation path, not only the homepage.
Avoid treating a shared office IP as one person. A crude IP block can affect many real users behind a network gateway. Start with the observed route and behavior, and review the false-positive rate before expanding restrictions.
Check both new-customer and existing-customer experiences. A checkout that silently stops creating required accounts can break later access even when payment succeeds. Use the gateway's test environment and a disposable authorized account for the rehearsal.
Clean up accounts with a recovery plan
Export a restricted-access inventory before deletion and identify accounts connected to orders, subscriptions, posts or support history. Use the relevant application's supported cleanup procedure. Do not assume a newly registered account has no business data.
For privileged access, follow the access-removal checklist, including machine credentials and sessions where relevant. Account deletion is not a substitute for patching the route that created it.
Measure the right outcome
Over the next few days, compare unwanted registrations, accepted legitimate signups, verification completion and customer complaints. Reduced signup totals alone are not success if customers are being rejected. Keep a dated record of the rule and the reason it was added.
Get registration troubleshooting help when several plugins own competing signup routes. The useful deliverable is a route-and-role map with a verified legitimate signup, not a promise that one CAPTCHA setting eliminates all spam.
Sources checked October 1, 2026. Instructions and visuals are explanatory, not claims of customer tests.