Executive brief
The Abandoned Contact Form 7 plugin for WordPress, which helps track incomplete form submissions, contains a security flaw that allows anyone to delete website content. An attacker can remotely remove posts, pages, or other site data without needing a password or any special permissions. This could lead to significant data loss and disruption of the website's operations.
Technical details
The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion due to a missing capability check and missing nonce validation in the action__remove_abandoned() function. This function is registered to both the wp_ajax_remove_abandoned and wp_ajax_nopriv_remove_abandoned hooks, making it accessible to unauthenticated users. The handler accepts a user-supplied 'recover_id' parameter via POST and passes it directly to wp_delete_post() with the force-delete flag enabled. Because the plugin fails to verify if the ID belongs to its specific 'cf7af_data' post type, an attacker can permanently delete any post, page, or media item on the site by sending a single AJAX request.
Affected products
- Abandoned Contact Form 7 Abandoned Contact Form 7 up to, and including, 2.2
Timeline
- 2026-06-16: disclosed: Vulnerability published on NVD
References
- https://plugins.trac.wordpress.org/browser/abandoned-contact-form-7/tags/2.2/inc/class.cf7af.php
- https://plugins.trac.wordpress.org/browser/abandoned-contact-form-7/tags/2.2/inc/class.cf7af.php
- https://plugins.trac.wordpress.org/browser/abandoned-contact-form-7/tags/2.2/inc/class.cf7af.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a38ebdeb-6ab8-4f1d-9c13-39211a9e97b6?source=cve