• Resolved colab1

    (@colab1)


    Within 2 hours of updating the WP Mail plugin to v1.8.1 an email was sent from the plugin advertising sex in the UK with a link that I’m sure is malicious. What is going on with the update that someone was able to exploit it almost instantly?

    This site is a new site still in dev but accessible to the world and there has been almost no activity on it for several weeks, I just logged in again for the first time yesterday and today I installed the plugin update and right away start getting this junk email. I’ve never had a problem with emails getting sent from the plugin prior to updating it today.

    Here is the email content as gmail shows it…(I’ve removed our email address that was listed as the From: address)

    Received: from 40838742610 named unknown by gmailapi.google.com with HTTPREST; Wed, 29 Jan 2020 20:36:01 -0800
    Date: Wed, 29 Jan 2020 20:36:01 -0800
    From: #######
    Reply-To: “\”Аdult fort st jоhn dating sitеs: https://xxxxxxx.com/datingsexygirlsinyourcity590111\”” <[email protected]>
    Message-Id: <CABDA31=WC8xxcH+w3r4a12qwzrzZFHRXUuTdYOD5UvEu6exoew@mail.gmail.com>
    X-Mailer: WPMailSMTP/Mailer/gmail 1.8.1
    MIME-Version: 1.0
    Content-Type: text/plain; charset=UTF-8
    Content-Transfer-Encoding: 8bit
    To: [email protected]
    Subject: New Message From

    Sеx dating in thе UK | Girls fоr sех in thе UK: https://xxxxx.com/datingsexygirlsinyourcity940355

Viewing 1 replies (of 1 total)
  • Hi @colab1,

    I apologize for the late response. WP Mail SMTP routes all the emails sent from your site through the SMTP you’ve configured. This includes the spam emails you’re receiving. You’ll need to find out the plugin sending such emails. You should be using spam prevention techniques such as reCAPTCHA, honeypot for any forms within your site.

    I hope this helps!

Viewing 1 replies (of 1 total)
  • The topic ‘Email About Sex in UK Sent Within 2 Hours of update to v1.8.1’ is closed to new replies.