{"id":19025905,"date":"2026-09-22T06:20:46","date_gmt":"2026-09-22T06:20:46","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/same-spam-message-template-getting-through-elementor-form-protection\/"},"modified":"2026-09-22T06:20:46","modified_gmt":"2026-09-22T06:20:46","slug":"same-spam-message-template-getting-through-elementor-form-protection","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/same-spam-message-template-getting-through-elementor-form-protection\/","title":{"rendered":"Same spam message template getting through Elementor form protection"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hi WP Armour team,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I\u2019m posting to report a consistent spam pattern that\u2019s getting past the Elementor form protection on <strong>multiple separate WordPress sites<\/strong> I manage. All sites have WP Armour installed with Elementor integration and honeypot actively enabled. What\u2019s happening<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Over the last few days, all of my sites have been receiving form submissions that use <strong>exactly the same core message structure<\/strong>, even though they\u2019re in different niches and hosted on different servers.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/i.postimg.cc\/FFCmxhjd\/wei-xin-tu-pian-20260922134856-527-105.png?ssl=1\" alt=\"\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The spam always follows this template:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">I would like more information. Please contact me by email \u2013 [random industry keyword]<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The name, email address and IP change between submissions, but this exact sentence line appears in every single one. It\u2019s clearly a distributed bot campaign targeting Elementor forms specifically. Sample submission details<\/p>\n\n\n\n<ul>\n<li>Message: <code>I would like more information. Please contact me by email \u2013 custom promotional products manufacturer.<\/code><\/li>\n\n\n\n<li>Example IP: <code>212.30.36.114<\/code><\/li>\n\n\n\n<li>Example User-Agent: <code>Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko\/20100101 Firefox\/123.0<\/code><\/li>\n\n\n\n<li>Form built with: native Elementor Form widget<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">My configuration<\/p>\n\n\n\n<ul>\n<li>WordPress: latest stable version<\/li>\n\n\n\n<li>Elementor Pro: up to date<\/li>\n\n\n\n<li>WP Armour: Elementor form protection activated, default honeypot rules enabled<\/li>\n\n\n\n<li>No other anti-spam plugins running<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">I wanted to check if this is a known bypass for the Elementor honeypot integration, and if there are any upcoming pattern updates or additional settings I can enable to block these.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thanks for your time and help.<\/p>\n","protected":false},"template":"","class_list":["post-19025905","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19025905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19025905\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19025905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}