Junglewise Threat Intelligence

CVE-2026-14487: WordPress Simple Coherent Form arbitrary file deletion in removeUploadDir

CVE-2026-14487 · Severity: critical · CVSS 9.1 · Published 2026-07-08

Executive brief

The Simple Coherent Form plugin for WordPress, used to create and manage website forms, contains a security flaw that allows anyone to delete files from the web server. By deleting critical system files like the site's configuration file, an attacker can take complete control of the website or cause a total service outage. This vulnerability can be exploited remotely without needing a username or password.

Technical details

The vulnerability exists in the `removeUploadDir` function of the Simple Coherent Form plugin due to a lack of path validation (CWE-22). An unauthenticated attacker can exploit this by obtaining a valid nonce from the `scf_get_id_upload` endpoint, which is accessible to any visitor. Furthermore, the secondary hash check for file removal is bypassable because it utilizes a hardcoded salt within the plugin's source code, allowing for offline forgery of the authorization token. By targeting sensitive files such as `wp-config.php`, an attacker can trigger a re-installation process to achieve remote code execution. All versions up to and including 2.4.13 are affected.

Affected products

  • tombgtn Simple Coherent Form up to, and including, 2.4.13

Timeline

  • 2026-07-08: disclosed: Vulnerability published in NVD dataset.
  • 2026-07-08: advisory: Wordfence published security advisory.

References