Junglewise Threat Intelligence

CVE-2026-6455: WP Contact Form 7 DB Handler CSRF leading to arbitrary file deletion

CVE-2026-6455 · Severity: high · CVSS 8.1 · Published 2026-05-28

Executive brief

The WP Contact Form 7 DB Handler plugin for WordPress, which stores contact form submissions in a database, contains a security flaw that allows for unauthorized file deletion. By tricking a site administrator into clicking a malicious link, an attacker can remotely delete critical website files, including configuration and system files. This can lead to a complete site outage or allow an attacker to reset the site to a vulnerable state for further compromise.

Technical details

The vulnerability exists in the process_bulk_action() function due to missing nonce verification when the _wpnonce field is omitted from the POST body. This CSRF flaw allows an attacker to trigger a UNION-based SQL injection because user-supplied input is used unparameterized in a numeric SQL context. By crafting a payload that returns a malicious serialized PHP array as post_content, the attacker can exploit unsafe deserialization. The resulting array values, if they contain the 'ys_cfdbh_file' key, are passed to wp_delete_file() without path traversal validation, enabling the deletion of arbitrary files such as wp-config.php. This issue is fixed in versions following 3.0.

Affected products

  • WP Contact Form 7 DB Handler WP Contact Form 7 DB Handler up to and including 3.0

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References