Viewing 11 posts - 1 through 11 (of 11 total)
  • Author
    Posts
  • #1064029

    Hello Ismael,
    we’re frequently receiving spam e-mails that are being sent via Enfold theme contact forms.
    The contact form is being send without filling out the defined mandatory fields. The only mandatory field, that is being filled out, is “Einwilligung zur Verarbeitung meiner personenbezogener Daten.” All the other mandatory fields e.g. Name, E-Mail, … are not being filled out.

    We’re using the most recent versions of everything (WordPress, Enfold, Plugins).

    I’d like to follow up our conversation with Ismael https://kriesi.at/support/topic/receiving-spam-through-contact-form/#post-1064020

    • This topic was modified 5 years, 9 months ago by jochenmaier.
    #1065522

    Hello, did you have the chance to take a look at this tocket?

    Kind regards, Jochen

    #1065678

    Hi,

    Have you enabled Captcha? That should help with the Bot messages.

    Best regards,
    Basilis

    #1065852

    Hello Basilis,
    yes – of course – this does not help.

    We’re frequently receiving spam e-mails that are being sent via Enfold theme contact forms.
    The contact form is being send without filling out the defined mandatory fields. The only mandatory field, that is being filled out, is “Einwilligung zur Verarbeitung meiner personenbezogener Daten.” All the other mandatory fields e.g. Name, E-Mail, … are not being filled out.

    You may want to have a look at the site – I’ve posted more information in the private section.

    Thanks, Jochen

    #1066294

    Hi,

    I would like to apologize for the late response.

    In the previous thread, I asked for the WP and FTP details or the access to your file server. Please include the FTP details in the private field along with the v2 and v3 keys for the reCAPTCHA widget that we will be installing in the site. You can get those keys from the Google reCAPTCHA admin console.

    // https://www.google.com/recaptcha/admin/site/

    Best regards,
    Ismael

    #1066323

    Hi Ismael,
    thanks for your reply.
    As Google Recaptcha is NOT compliant with EU-GDPR, we will NOT install this plugin.

    My question is: How is it possible, that a form is being sent WITHOUT filling out the mandaytory fields as defined in Enfold?
    Please have a look ath this question.

    Thanks!
    BR, Jochen

    #1066537

    Hi,

    How is it possible, that a form is being sent WITHOUT filling out the mandaytory fields as defined in Enfold?

    I explained that in the previous thread.

    // https://kriesi.at/support/topic/receiving-spam-through-contact-form/#post-918851

    Unfortunately, we can’t do much about that aside from installing the reCAPTCHA plugin.

    Best regards,
    Ismael

    #1066556

    Hi,
    this is obviously a bug in Enfold, and the only thing that you’re telling me is: “we can’t do much about that” ???

    Again: How can it be, that mandatory fields DO NOT need to be filled out?
    This has NOTHING to do with a Captcha plugin.

    Rgds, Jochen

    #1067481

    Hi Jochen,

    Thanks for the update.

    As previously stated on the other thread, they can get around the verification by removing the script validation. Now, I don’t know how they do that exactly, but it is possible. Unfortunately, we can do much about it aside from offering a new type of contact form security such as the reCAPTCHA widget. If that is not possible then we’ll have to suggest that you look for a plugin such as Contact Form 7 or Gravity Forms as an alternative to the theme’s contact form.

    // https://wordpress.org/plugins/contact-form-7-honeypot/
    // https://www.gravityforms.com/rip-captcha/

    FYI, the reCAPTCHA widget is now available on version 4.5.4 in case you change your mind.

    Best regards,
    Ismael

    #1104136

    Ismael,
    Just curious… Why cant Enfold incorporate a Honeypot into their Contact Form?

    #1104725

    Hey!

    We answered here:

    // https://kriesi.at/support/topic/spam-emails-being-set-through-contact-forms/#post-1104723

    Have you tried the actual recaptcha option in the theme? You’re probably referring to the plugin version of the recaptcha widget, which is now integrated in the theme and is using the database transient option to block spams. That layer is not available in the plugin version.

    If you have more questions, please kindly your own ticket or thread.

    Best regards,
    Ismael

Viewing 11 posts - 1 through 11 (of 11 total)
  • You must be logged in to reply to this topic.