PT-2026-56313 · WordPress · Simple Coherent Form

·

CVE-2026-14487

·

Published

2026-07-08

·

Updated

2026-07-08

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Coherent Form versions prior to 2.4.14
Description Insufficient file path validation in the removeUploadDir() function allows unauthenticated attackers to delete arbitrary files on the server. This can lead to remote code execution if critical files, such as wp-config.php, are deleted. The issue is facilitated by the 'scf get id upload' endpoint, which provides a valid scf upload file removal nonce to unauthenticated visitors. Additionally, the secondary hash check in the removal endpoint is forgeable offline because it uses a hardcoded salt embedded in the plugin source, failing to provide a secure authorization boundary.
Recommendations Update Simple Coherent Form to version 2.4.14 or later.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14487

Affected Products

Simple Coherent Form