• Resolved Myakish

    (@myakish)


    Hi All,

    My provider claims that the spam from the feedback form on my website comes from the phpMailer version 5.2.22 module. Spam copies the old format of the letter and now differs from messages from the feedback form.
    Is it right that phpMailer 5.2.22 really vulnerable and what should be done to fix it?

    p.s. Current version phpMailer 6.06

    • This topic was modified 6 years, 3 months ago by Myakish.
Viewing 7 replies - 1 through 7 (of 7 total)
  • Sorry, is that a plugin you are using?

    Thread Starter Myakish

    (@myakish)

    Contact Form 7. Last version. WP last version too.

    So just to be clear, you are having issues with Contact Form 7 and WP 4.9.8?

    Thread Starter Myakish

    (@myakish)

    Yes, right. I use the latest version of CF7 and WP.
    I discovered this problem when I changed the settings of the letter to Contact 7: I changed the sender’s address and the text of the letter for the feedback form. Spam emails use old format. The provider has confirmed the use of phpMailer when sending spam emails. phpMailer is a part of WP and I don’t know what to do

    Thread Starter Myakish

    (@myakish)

    updated wordpress to version 5.0

    Thread Starter Myakish

    (@myakish)

    All problems solved, thanks

    But what if you’re using WP 5.2, not using any contact form plugin? Could it be that our WP theme (Divi) has a compromised form mailer built in?

    We’re getting some spam messages from “Eric”…

    X-PHP-Originating-Script: 30768:class-phpmailer.php
    Date: Wed, 8 May 2019 13:10:37 +0000
    From: Eric <[email protected]>
    Reply-To: “\”Eric\”” <[email protected]>
    Message-ID: <[email protected]>
    X-Mailer: PHPMailer 5.2.22 (https://github.com/PHPMailer/PHPMailer)
    MIME-Version: 1.0
    Content-Type: text/plain; charset=UTF-8
    Content-Transfer-Encoding: 8bit

    When we test the contact form on our site (it came as part of the theme) it sends the below format which is what we expect. A test email from our contact form goes to our [email protected] email acct…

    Tester <[email protected]> via gator4156.hostgator.com
    reply-to: Tester <[email protected]>
    to: [email protected]
    date: May 10, 2019, 9:38 PM
    subject: New Message From Our Site
    mailed-by: gator4156.hostgator.com
    security: Standard encryption (TLS) Learn more

    Does running an old version of php allow the php mailer to be compromised? Is that a stupid question with an “of course does” answer?

    Sometimes we log into one of our sites and see that contact 7 has been added to plugins, when we don’t even use it. Might a hacker add to a site to take advantage of an older version of php being used?

    Sadly our sites at HostGator don’t seem to get the auto-updates our other hosting provides.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘phpMailer 5.2.22’ is closed to new replies.