Junglewise Threat Intelligence

CVE-2026-9187: Abandoned Contact Form 7 arbitrary post deletion via action__remove_abandoned

CVE-2026-9187 · Severity: medium · CVSS 5.3 · Published 2026-06-16

Executive brief

The Abandoned Contact Form 7 plugin for WordPress, which helps track incomplete form submissions, contains a security flaw that allows anyone to delete website content. An attacker can remotely remove posts, pages, or other site data without needing a password or any special permissions. This could lead to significant data loss and disruption of the website's operations.

Technical details

The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion due to a missing capability check and missing nonce validation in the action__remove_abandoned() function. This function is registered to both the wp_ajax_remove_abandoned and wp_ajax_nopriv_remove_abandoned hooks, making it accessible to unauthenticated users. The handler accepts a user-supplied 'recover_id' parameter via POST and passes it directly to wp_delete_post() with the force-delete flag enabled. Because the plugin fails to verify if the ID belongs to its specific 'cf7af_data' post type, an attacker can permanently delete any post, page, or media item on the site by sending a single AJAX request.

Affected products

  • Abandoned Contact Form 7 Abandoned Contact Form 7 up to, and including, 2.2

Timeline

  • 2026-06-16: disclosed: Vulnerability published on NVD

References