Got an email this morning by a client, who was blocked by his ISP due to excessive amounts of emails going out.
After some digging, with help from the ISP helpdesk, it turned out to be the contactform in Enfold being mis-used.
We upgraded to the latest version of Enfold today from 4.5, and ran a fine comb through all the settings of WP and Enfold again. We also changed all passwords for the accounts too.
To be fair, the contact form was just using the basic functionality, no spam related plugins or filters.
We removed the contact form from the website all together, but I want to be sure if the contact form code is not still being used únder the hood’ for purposes like this.
cheers!
rob
Hey Rob,
I’m sorry for the problem, I haven’t heard of this happening before though. The contact form is designed to receive emails, not send them out. Are you sure that it wasn’t the WordPress installation, or an email account, which was hacked?
Best regards,
Rikard
Hi Rikard,
According to the ISP help-desk, it was the form sending out emails with the email address linked to the form.
Like I said, we removed the form from the page, checked all settings and plugins, and reset all the passwords on the WP accounts.
So far it seems to did the trick.
And yes, I found it a bit odd this would/could happen. Unfortunately the help-desk was a bit vague sometimes, and not entirely clear on what happened exactly.
I’ll keep an eye on this though.
cheers for the reply.
rob