I'm using S2Member 3.5.8 on Wordpress 3.1.2 and I have been allowing free subscribers to my site.
In my registration page, I capture some custom fields, one of which is a drop down list so a value will always be supplied.
Late yesterday, I noticed a sudden spike in registration activity, I received ten new members in the space of an hour or so. My stats didn't seem to have recorded enough traffic to justify the new members.
On further investigation I found that none of the new members had any of my S2Member custom fields populated so they cannot have gone through the standard registration page.
I locked the site down overnight (password protected the directory). This morning, I opened it up again and within 5 minutes, I had another 2 registrations.
Clearly there's a bot working somewhere and bypassing the normal registration to create these new users.
It would also seem clear that there must be some vulnerability on the site that is allowing these automated registrations to take place.
I don't know if this is an S2Member issue or a Wordpress issue, but, I thought it best to report it to both parties, because it is an issue.
In the interim, I've disabled free user registration in S2Member and the problem has stopped.
best regards
Fraser