• Resolved ebouilleur

    (@ebouilleur)


    Hello,

    I just noticed that my site is sending spam to a lot of people. I use the WPForms plugin (and WP Mail SMTP) as an email form and emails are sent via Brevo (formerly sendingblue).

    In my form, I have activated the sending of notifications to 1 defined email.

    Except when I look at the Brevo logs, I see that I am sending lots of spam (with the email title that comes from my form) and to unknown recipients (CF PJ).

    So, have I missed something in my config (I doubt it) or are there major security vulnerabilities in WPForms?

    thank you for your opinion.

    The page I need help with: [log in to see the link]

Viewing 11 replies - 1 through 11 (of 11 total)
  • Plugin Support Ralden Souza

    (@rsouzaam)

    Hi @ebouilleur,

    Thanks for reaching out!

    I believe you configured your form to send the notification to users who filled the form, and this would be related to the issue. In case it helps, please check our tutorial on how to do this.

    You could verify your notification settings and temporarily configure your form to send notifications only to a specific email address.

    To prevent spammers in your form(s), we have some anti-spam options.

    In WPForms Lite, we have a built-in anti-spam option which is enabled by default in the form builder > Settings > General (see screenshot here).

    We also have integration with Google’s free reCAPTCHA service. In case it helps, here’s a detailed tutorial on how to set up reCAPTCHA in WPForms.

    And if you’d prefer not to use reCAPTCHA, we have another anti-spam protection feature, hCaptcha. This is a good option if you’d prefer not to sign up for Google’s reCAPTCHA service. Within your forms, hCaptcha will display a checkbox asking users to prove they’re human (much like Google’s v2 Checkbox reCAPTCHA). We have a detailed guide for setting up hCaptcha.

    Another option you might want to consider is setting up the Akismet anti-spam protection. This option will allow you to integrate Akismet which is one of the top anti-spam protection plugins on www.ads-software.com to your forms. You should be able to seamlessly set this up by following the instructions here.

    Alternatively, you can consider the third-party plugins such as WordPress Zero Spam or Spam protection, AntiSpam, FireWall by CleanTalk which work out of the box to protect your forms against spam.

    Hope this helps!

    Thread Starter ebouilleur

    (@ebouilleur)

    Hi,

    I understand i can use anti spam, but trouble is not about that.

    Trouble is this plugin allow send mail to a different “TO” that I indicate in the configuration (mail in notification input)…

    Plugin Support Ralden Souza

    (@rsouzaam)

    Hi @ebouilleur,

    When you get a chance, could you please share a screenshot from the notification settings of the form on https://www.dessaude-frederick.fr/contact-2/? With this, I may be able to provide further details about the issue.

    Also, please know that I was not able to submit the form on https://www.dessaude-frederick.fr/contact-2/, and I believe it’s because of the issue with Google reCAPTCHA reported on the Console – screenshot: https://a.supportally.com/i/mfl96I.

    Thanks!

    Prashant Rai

    (@prashantrai)

    Hey @ebouilleur – I’m Prashant filling in for my colleague Ralden ??

    We haven’t heard back from you since the last message my colleague posted, so I’m going to go ahead and close this thread for now. But if you’d like us to assist further, please feel welcome to continue the conversation.

    Thanks!

    Thread Starter ebouilleur

    (@ebouilleur)

    Hi,
    Screen of the notification here : https://ibb.co/K2mZf9X

    I’m looking for this trouble of version of jquery, but i dont know why yet.

    Plugin Support Ralden Souza

    (@rsouzaam)

    Hi @ebouilleur,

    Thanks for the screenshot!

    From it, we can see you configured your form to send a copy to the email address filled in the Email field.

    With this, I recommend removing the smart tag from the CC field and test if the issue continues.

    I hope this helps!

    Plugin Support Ralden Souza

    (@rsouzaam)

    Hi @ebouilleur,

    We haven’t heard back from you in a few days. If you’d like more help with using WPForms Lite, please feel free to reach out.

    Thanks!

    Thread Starter ebouilleur

    (@ebouilleur)

    Hi,

    Yes issue continues without de CC, so the plugin is unsecure.

    I put captcha now, so robot are block. i’m look for a best secure plugin.

    Regards

    Plugin Support Ralden Souza

    (@rsouzaam)

    Hi @ebouilleur,

    Thanks for letting me know!

    However, I continue not being able to submit the form on https://www.dessaude-frederick.fr/contact-2/, and I get this error on the Console: “Uncaught ReferenceError: grecaptcha is not defined”.

    When you get a chance, could you please record a video showing the issue? That way, I may see what is causing the issue and can provide further information about it.

    Thanks!

    Thread Starter ebouilleur

    (@ebouilleur)

    Hi,

    I force a reinstall of WP last version and it’s ok, i can send message (no error on console log).

    Regards

    Plugin Support Ralden Souza

    (@rsouzaam)

    Hi @ebouilleur,

    Great to hear that, thanks for letting us now!

    If you’d like more help with using WPForms Lite, please feel free to reach out.

    Thanks!

Viewing 11 replies - 1 through 11 (of 11 total)
  • The topic ‘Sending spam’ is closed to new replies.