Same spam message template getting through Elementor form protection
-
Hi WP Armour team,
I’m posting to report a consistent spam pattern that’s getting past the Elementor form protection on multiple separate WordPress sites I manage. All sites have WP Armour installed with Elementor integration and honeypot actively enabled. What’s happening
Over the last few days, all of my sites have been receiving form submissions that use exactly the same core message structure, even though they’re in different niches and hosted on different servers.

The spam always follows this template:
I would like more information. Please contact me by email – [random industry keyword]
The name, email address and IP change between submissions, but this exact sentence line appears in every single one. It’s clearly a distributed bot campaign targeting Elementor forms specifically. Sample submission details
- Message:
I would like more information. Please contact me by email – custom promotional products manufacturer. - Example IP:
212.30.36.114 - Example User-Agent:
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0 - Form built with: native Elementor Form widget
My configuration
- WordPress: latest stable version
- Elementor Pro: up to date
- WP Armour: Elementor form protection activated, default honeypot rules enabled
- No other anti-spam plugins running
I wanted to check if this is a known bypass for the Elementor honeypot integration, and if there are any upcoming pattern updates or additional settings I can enable to block these.
Thanks for your time and help.
- Message:
You must be logged in to reply to this topic.