Briefing

Contact Form Spam After Deactivation

security
by /u/pdx_flyer · WordPress

Inspect server logs to locate the spam source, block offending IPs, and ensure no residual form handling code remains.

What to do now

Check server logs for request source, block IPs, verify no residual form handling code, consider adding a honeypot or reCAPTCHA, update WordPress core, and ensure no malicious code remains.

Summary

I have been using Contact Form 7 to handle a single contact form on my WordPress site.

A few days ago I started receiving spam emails that match the format of my contact form. I added a CAPTCHA, but the spam kept coming, so I disabled the form. The spam still arrives.

I deactivated and deleted the plugin, yet I continue to get spam emails formatted like the form. I have no other contact forms on the site and am unsure how to block the source.

Key changes

  • Spam emails persist after disabling Contact Form 7
  • Spam format matches the original form fields
  • No other contact forms are present on the site
  • Spam continues after plugin removal

Affects

wp-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting