PT-2026-56313 · WordPress · Simple Coherent Form
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Simple Coherent Form versions prior to 2.4.14
Description
Insufficient file path validation in the
removeUploadDir() function allows unauthenticated attackers to delete arbitrary files on the server. This can lead to remote code execution if critical files, such as wp-config.php, are deleted. The issue is facilitated by the 'scf get id upload' endpoint, which provides a valid scf upload file removal nonce to unauthenticated visitors. Additionally, the secondary hash check in the removal endpoint is forgeable offline because it uses a hardcoded salt embedded in the plugin source, failing to provide a secure authorization boundary.Recommendations
Update Simple Coherent Form to version 2.4.14 or later.
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Coherent Form