I have a site that's been up 15 years and it's been going smooth until the other day when I decided to make my GRAV install live. 12 hours after this happened, the system email address started being used by bots/spammers to send thousands of emails from my server and my email address.
What is going on? I change my email address password and I'm talking with support about getting the smtp password changed, but this is insane. What kind of serious problem is there with GRAV that something can use it to send thousands of spam emails?
I'm open to any suggestions, but I'm this close to completely walking away from GRAV and putting my old system back up because something this insecure is just crazy.
Is there any way to track how this could be happening within GRAV? Any logs that I can look at?
The one thing I know is that this is related to GRAV so I'm hoping someone here has some good ideas.
One thing- I just disabled the "email" plugin by selecting "disabled" for the email engine, hopefully that will help.