Thank you very much for the very helpful reply, I did as you suggested and got it working. I also looked logged in to Wordpress for the first time in many months, and Holy Batman, nearly 4000 spam comments! Funny how my other site, that I coded myself in PHP, gets NO spam comments or accounts at all despite having only a very simple "real person checker", while this WordPress one just got absolutely flooded.
Maybe I should just rewrite the whole thing on my own... on the other hand, it feels a bit like defeat - I've read that WordPress CAN be made secure...