Title: Spam Attack Vulnerability
Last modified: August 30, 2016

---

# Spam Attack Vulnerability

 *  [squibm](https://wordpress.org/support/users/squibm/)
 * (@squibm)
 * [11 years, 2 months ago](https://wordpress.org/support/topic/spam-attack-vulnerability/)
 * Hi. I’ve been running subscribe2 for several years. Last week spammers were able
   to use the executable to spew 25,000 junk mails from our server using the exim
   mail utility. Here is an entry from the /var/log/exim_mainlog:
 * 2015-08-06 07:41:00 cwd=/home/gowhn/public_html/blog-subdir/wp-content/plugins/
   subscribe2 4 args: /usr/sbin/sendmail -t -i [-fsnamechanged@me.com](https://wordpress.org/support/topic/spam-attack-vulnerability/-fsnamechanged@me.com?output_format=md)
   
   2015-08-06 07:41:00 1ZNLPo-0002rw-6Q <= [NameAlsoChanged@me.com](https://wordpress.org/support/topic/spam-attack-vulnerability/NameAlsoChanged@me.com?output_format=md)
   U=gowhn P=local S=1415 id=c01e8363ee09ecf26a3e8bdd097a7bff@domainchanged.com 
   T=”Re:Adorable blonde strips spreads” from <AlsoNameChanged@me.com> for [AnotherNameChanged@yahoo.com](https://wordpress.org/support/topic/spam-attack-vulnerability/AnotherNameChanged@yahoo.com?output_format=md)
 * Please evaluate the security vulnerability by assuring that it is wordpress that
   is calling the script, or preventing the script from activation from the mail
   via naked SMTP with a cmd= parameter.
 * Presentation of the arguments to the script enabled the script to run, and then
   stuffed my mail server with messages at the whim of the calling program. All 
   the hacker had to do was “guess” the directory where subscribe2 was installed.
   Subscribe2 was disabled at the time the exploit occurred.
 * [https://wordpress.org/plugins/subscribe2/](https://wordpress.org/plugins/subscribe2/)

Viewing 1 replies (of 1 total)

 *  [Matt Robinson](https://wordpress.org/support/users/mattyrob/)
 * (@mattyrob)
 * [11 years, 1 month ago](https://wordpress.org/support/topic/spam-attack-vulnerability/#post-6424162)
 * [@squibm](https://wordpress.org/support/users/squibm/)
 * As far as I can tell none of the core Subscribe2 files can be called directly
   as they employ the recommended WordPress security fail safes of ensuring WordPress
   is running first.
 * Additionally, all email functionality within Subscribe2 is performed via the 
   core WordPress wp_mail() function so any attempt to directly call the plugin 
   files would fail if WordPress has not been called as the core functions wouldn’t
   be available.
 * I suspect your site was compromised some other way and the spammers had access
   to the admin area of your site at the time of the email creation.

Viewing 1 replies (of 1 total)

 The topic ‘Spam Attack Vulnerability’ is closed to new replies.

 * ![](https://ps.w.org/subscribe2/assets/icon-256x256.png?rev=3696642)
 * [Subscribe2 - Form, Email Subscribers & Newsletters](https://wordpress.org/plugins/subscribe2/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/subscribe2/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/subscribe2/)
 * [Active Topics](https://wordpress.org/support/plugin/subscribe2/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/subscribe2/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/subscribe2/reviews/)

 * 1 reply
 * 2 participants
 * Last reply from: [Matt Robinson](https://wordpress.org/support/users/mattyrob/)
 * Last activity: [11 years, 1 month ago](https://wordpress.org/support/topic/spam-attack-vulnerability/#post-6424162)
 * Status: not resolved