Tell us what you are trying to do? I have a CRED form connected to horse profile pages (See here: hidden link). However, somehow spammers are getting to the "raw" form that is not connected to any pages. Is there a way to prevent this from happening?
Is there any documentation that you are following?
Is there a similar example that we can see?
What is the link to your site? See how form is set up on front end here: hidden link
Hello,
I have checked the URL you mentioned above, you are using reCAPTCHA in the post form, you can raise the limitation of reCAPTCHA by following Google document:
hidden link
But can you see how they are accessing the form when it is not attached to a page? Because the spam messages are not coming from any of the horse pages, otherwise they would have the horse name included in the title of the email instead of it saying %%FIXED_PARENT_TITLE%%.
No, user can only access to Toolset post from where you display it in frontend.
I suggest you try to get your website logs, find where they get to your website