PT-2026-44199 · Yudiz+1 · Wp Contact Form 7 Db Handler

·

CVE-2026-6455

·

Published

2026-05-27

·

Updated

2026-05-28

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Contact Form 7 DB Handler versions prior to 3.1
Description This issue involves Cross-Site Request Forgery (CSRF) that can lead to arbitrary file deletion through SQL Injection and PHP Object Injection. The flaw exists in the process bulk action() function due to missing nonce verification, as the check is only performed if the wpnonce variable is present in the POST body. This allows an attacker to bypass the security check by omitting the field. Furthermore, the function uses an unsanitized, unparameterized user-supplied value in a numeric SQL context (WHERE ID = $ID) and performs unsafe deserialization of the post content field from the query result. An attacker can trick a logged-in administrator into triggering a UNION-based SQL injection payload that returns a malicious serialized PHP array. During deserialization, values associated with keys containing ys cfdbh file are used as file paths and passed to wp delete file() without path traversal validation, enabling the deletion of arbitrary server files such as wp-config.php.
Recommendations Update WP Contact Form 7 DB Handler to a version later than 3.0. As a temporary mitigation, restrict administrative access to the plugin settings to trusted IP addresses to reduce the risk of CSRF attacks.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6455

Affected Products

Wp Contact Form 7 Db Handler