WordPress.org

Forums

WP Ajax Edit Comments
[resolved] Someone emailed a commenter through the plugin? (6 posts)

  1. slobizman
    Member
    Posted 2 years ago #

    Just had something really strange happen. A user of a website of mine said he received an strange email and it says it was from our site. I asked him to send the headers. They follow below.

    I'm posting here in this forum because of this line:

    X-Source-Dir: useraccountmedia.com:/public_html/wp-content/plugins/wp-ajax-edit-comments/php

    Does this mean that the email was created by this plugin?

    (I've changed some domain and user info in this to disguise my server info)

    x-store-info:fHNTDlzCF8Nxw6HwcfGQy+S7Ax/lqLSmNphQ3OF+T9E=
    Authentication-Results: hotmail.com; spf=none (sender IP is xx.xxx.xxx.xx) smtp.mailfrom=useraccount@host3.mysite.com; dkim=none; x-hmca=none
    X-AUTH-Result: NONE
    X-SID-Result: NONE
    X-Message-Status: n:n
    X-Message-Delivery: Vj0xLjE7dXM9MDtsPTE7YT0wO0Q9MjtHRD0yO1NDTD00
    X-Message-Info: 5cuOr7VrmjBwCXgOIB2nrtfBWP/ZRZ5MFsMPQuLj/Tb9am9RaMk4prrlvVceZDpFHLLUY/WOE6JDwR4k9bkYpJRPt5HfODCZjUmsMm/OyD4wgeTuxHzostze7BvrEL2scoKzX3VkejwJouZntQtAbFsNFKH1aiXY
    Received: from host3.mysite.com ([xx.xxx.xxx.xx]) by SNT0-MC4-F10.Snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);
    	 Wed, 20 Feb 2013 20:37:03 -0800
    Received: from useraccount by host3.mysite.com with local (Exim 4.80)
    	(envelope-from <useraccount@host3.mysite.com>)
    	id 1U8Nu2-0005Ea-US
    	for xxxxxxxx@hotmail.com; Wed, 20 Feb 2013 23:37:02 -0500
    To: xxxxxxx@hotmail.com
    Subject: You close to Orlando?
    Date: Thu, 21 Feb 2013 04:37:02 +0000
    From: IHTM <>
    Message-ID: <0a73a7d3a2fd6225daf3587b2e4d9f4e@www.useraccountmedia.com>
    X-Priority: 3
    X-Mailer: PHPMailer (phpmailer.sourceforge.net) [version 2.0.4]
    MIME-Version: 1.0
    MIME-Version: 1.0
    Content-Transfer-Encoding: 8bit
    Content-Type: text/plain; charset="UTF-8"
    X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
    X-AntiAbuse: Primary Hostname - host3.mysite.com
    X-AntiAbuse: Original Domain - hotmail.com
    X-AntiAbuse: Originator/Caller UID/GID - [509 32007] / [47 12]
    X-AntiAbuse: Sender Address Domain - host3.mysite.com
    X-Get-Message-Sender-Via: host3.mysite.com: authenticated_id: useraccount/only user confirmed/virtual account not confirmed
    X-Source: /usr/bin/php
    X-Source-Args: /usr/bin/php
    X-Source-Dir: useraccountmedia.com:/public_html/wp-content/plugins/wp-ajax-edit-comments/php
    Return-Path: useraccount@host3.mysite.com
    X-OriginalArrivalTime: 21 Feb 2013 04:37:03.0767 (UTC) FILETIME=[18C6CA70:01CE0FED]
    
    Curious if you\'re very close to Orlando area?

    http://wordpress.org/extend/plugins/wp-ajax-edit-comments/

  2. Ronald Huereca
    Member
    Plugin Author

    Posted 2 years ago #

    Yes, one of the features is that an editor/administrator can send a commenter an e-mail through the plugin.

  3. Ronald Huereca
    Member
    Plugin Author

    Posted 2 years ago #

    You can also disable the e-mail feature by going into AEC -> Appearance and unchecking the e-mail feature.

  4. slobizman
    Member
    Posted 2 years ago #

    Thanks for the reply Ronald. But there are only two of us with Administrator/Editor accounts, and neither of us emailed the person.

  5. Ronald Huereca
    Member
    Plugin Author

    Posted 2 years ago #

    I just double-checked. The author of the post can also e-mail commenters. That's what it probably was.

    If not, then someone else that is fishy is going on.

    I would recommend just disabling the feature in AEC->Appearance if you don't want this functionality present.

  6. slobizman
    Member
    Posted 2 years ago #

    Aha! That must have been it. And yes, I'll disable the feature.

    Thanks so much for getting back to me so quickly.

Topic Closed

This topic has been closed to new replies.

About this Plugin

About this Topic

Tags

No tags yet.