Skip Navigation

[Resolved] CRED form getting spammed

This support ticket is created 2 years, 9 months ago. There's a good chance that you are reading advice that it now obsolete.

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 9:00 – 13:00 9:00 – 13:00 9:00 – 13:00 9:00 – 13:00 9:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Supporter timezone: Asia/Hong_Kong (GMT+08:00)

This topic contains 3 replies, has 2 voices.

Last updated by Luo Yang 2 years, 9 months ago.

Assisted by: Luo Yang.

Author
Posts
#2300443
Screenshot 2022-02-22 at 16-15-16 Inquiry for %%FIXED_PARENT_TITLE%% - carolynne equiluxemarketing com - Nicole Robertson M[...].png

Tell us what you are trying to do? I have a CRED form connected to horse profile pages (See here: hidden link). However, somehow spammers are getting to the "raw" form that is not connected to any pages. Is there a way to prevent this from happening?

Is there any documentation that you are following?

Is there a similar example that we can see?

What is the link to your site? See how form is set up on front end here: hidden link

#2300703

Hello,

I have checked the URL you mentioned above, you are using reCAPTCHA in the post form, you can raise the limitation of reCAPTCHA by following Google document:
hidden link

#2301385

But can you see how they are accessing the form when it is not attached to a page? Because the spam messages are not coming from any of the horse pages, otherwise they would have the horse name included in the title of the email instead of it saying %%FIXED_PARENT_TITLE%%.

#2301607

No, user can only access to Toolset post from where you display it in frontend.

I suggest you try to get your website logs, find where they get to your website