Skip to main content

Threat intelligence

Abandoned Contact Form 7 <= 2.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'recover_id' Parameter

CVE-2026-9187 · abandoned-contact-form-7

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Abandoned Contact Form 7 at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Abandoned Contact Form 7 <= 2.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'recover_id' Parameter
Affected software
abandoned-contact-form-7(Plugin)
Affected versions
  • ≤ 2.2
Authentication
Unauthenticated
Vulnerability type
Other
Published
15 June 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory a38ebdeb-6ab8-4f1d-9c13-39211a9e97b6). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Abandoned Contact Form 7 version against this catalog when the Defence plugin is connected to your WordPress site.