Well, things have changed in the past 24 hours and I believe we may have plugged the hole. Some sort of PHP exploit was being used to do html insertion and we think it was WordPress. aSince updating to the latest version we have seen the problem go away. My thoughts on Freeform are that the exploit was capable of using forms - but that’s just a guess 😊