It seems Contact Form 7 allows you to specify the recipient via a select dropdown. This means that the recipient e-mail address is stored in the form and sent to the server, which then just reads it. Unless the server then verifies the recipient address was one of the options you specified, this can be a “security hole” to send spam to other e-mail addresses.
It would work like this: the server is prepared to read the recipient
select field, in case you specified one. But even if you did not specify one, the spambot can send a recipient
field value to the server, tricking it into thinking it came from a real HTML dropdown. This allows it to specify any value it wants there.
It is possible that Contact Form 7 prevents this kind of attack, but you should check this yourself, I have no further experience with Contact Form 7.
Related Posts:
- how to reduce the number of spam comments
- A spam bot loves me, what can I do?
- How to spam-filter a custom content type with the Akismet plugin?
- Getting trackback spam, even with trackbacks disabled
- How to block a someone from commenting?
- Reducing spammy user sign-ups
- How to reduce spam
- How do I permanently disable Pingbacks?
- What are all these spam subscribers doing here?
- How to disable WordPress trackbacks?
- How can I delete all my existing trackbacks?
- How can I delete all users which have never commented / have posted spam comments?
- Comment Spammed vs Trashed
- getting casino links on my woocommerce site [closed]
- How to locate & delete hidden pages on a site
- How is my non-published blog getting so much spam?
- Contact Form 7 Plugin send emails to my Gmail as spam [closed]
- Automated spam being caught in 2 posts. Can this be used to help get rid of spam on everyone’s sites?
- WordPress Site has 35K spam images
- WordPress Phone Verification
- Is the tagline area spam-bot proof?
- Spam email sent from my [email protected] account
- How to block spam blocks pointing to a same website [closed]
- WordPress VPS out of Memory Problem
- Is it possible to determine proxy based comments?
- How to track down a phantom contact form?
- How to get rid of spam forever?
- Spams, Scams on WordPress site – what to do?
- Auto block ALL IP’s indicated by Akismet?
- How to Prevent Unwanted Spam to Contact Form 7 [closed]
- Simple comments spam solution
- How to stop people from using my domain to send spam? [duplicate]
- how to trash WordPress comments if its not in English
- WordPress and wamp sending “Delivery status notification Failure” to my inbox every 7 minutes
- Why do I get comment spam even with Akismet and Captcha?
- How to add placeholder for contact form7 for dropdown? [closed]
- How to use other shortcodes inside Contact form 7- forms? [closed]
- Contact form 7 select box different value-text than content-text in option [closed]
- Why might a plugin’s ‘do_shortcode’ not work in an AJAX request?
- Removing the “Website” Field from Comments and Replies?
- How to modify Contact Form 7 Success/Error Response Output [closed]
- Why “Contact Form 7” doesn’t update PHPmailer library?
- Contact Form 7 – Populate Select List With Taxonomy [closed]
- Experiences with adding Nonces to the comment form
- Tips for finding SPAM links injected into the_content
- How to get current post ID in Contact Form 7 wpcf7_before_send_mail hook action
- Contact Form 7 – process form using a PHP script, instead of mailing [closed]
- To Disable WordPress Rest API or Not To Disable?
- How to execute a server side script when contact form 7 is submitted? [closed]
- How to deal with small scale comment spam on small commercial sites? [closed]
- Contact Form 7 – add custom function on email send [closed]
- What methods should be used to fend off splogs in a multiuser install? [closed]
- What’s the easiest way to close comments on media/attachments?
- How to resolve “Failed to send your message” problem for Contact Form 7? [closed]
- contactform7 remove tags with “wpcf7_autop false” from functions.php
- Contact Form 7 Custom Post Action
- How can I send to multiple Contact Form 7 recipients based on form input? [closed]
- Contact Form 7: wp_mail doesn’t work after update to 4.6
- How to remove comment spam in WordPress
- How is comment spam received without a comments form?
- Local wordpress setup with SPAM in the incoming links dashboard section?
- How to choose email recipient in Contact Form 7 based on address state input in form and save to database [closed]
- How to prevent spam users registering even with registration disabled
- Allow anonymous comments, but prevent spam [closed]
- Adding a hyperlink to the checkbox in the contact form 7 [closed]
- Creating a contact form without a plugin [closed]
- How exactly does Bad Behavior plugin work?
- Is there any advantage to emptying comment spam?
- Why do I get email notifications about comments that WordPress has already determined are spam?
- How to Translate Contact Form 7 using qTranslate? [closed]
- show image in mail contact form 7 [closed]
- Horizontal (columned) Contact form 7 and acceptance field on devices
- Number of External Links in Comments – Moderation Option
- using 1 form shortcode (si or cf7) for all multisite sites [closed]
- Dynamically send pdf attached to post with contact form 7 [closed]
- Passing a variable into Contact Form 7 [closed]
- Comments screen in backend, how to disable Quick Edit | Edit | History | Spam | for non admins
- How to save contact form 7 data in Custom Post Types (CPT) [closed]
- Check spam in custom form – akismet
- Mass delete spam accounts
- Contact form 7 Dynamic text – placeholder on GET field
- What is the best way to avoid spammers registering to my blog?
- Transferring contact form input to an email account without using an email-proxy
- WordPress Contact Form 7: populate the value of a field dynamically with PHP [closed]
- Contact Form 7 – Populating dropdown list with terms relative to the post
- What do spammers gain by signing up as a user?
- Vue.js + AJAX Shortcode
- Contact form 7 dynamic text extension – populate form with title from previous page [closed]
- Custom contact form 7 select with custom values [closed]
- Contact Form 7 plugin refreshing page on submit [closed]
- Upload files – total size limit – WordPress/Contact Form 7
- ACF + contact form 7
- Strategies for coping with hyperagressive spambots?
- Contact Form 7 + Configure SMTP: Sender email appearing as my own email [closed]
- How to disable autocomplete for inputs in contact form 7? [closed]
- Website is being flooded [closed]
- How Do I Prevent Junk Account Creation?
- Insert Captcha Code info Any Form (Created of Plugin)
- How to programmatically send additional notification emails in Contact form 7 [closed]
- Store and Encrypt Contact Form 7 Submissions in Database? [closed]