Skip to content
COOEY

EXPOSURES › CVE-2026-14487

CVE-2026-14487

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-08 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-14487 ↗
⚡ RCE SHAME 45/100 rceunpatchedexploited-in-wild

A WordPress plugin allows unauthenticated attackers to delete critical system files, enabling remote code execution.

CVE-2026-14487 in the Simple Coherent Form plugin permits unauthenticated attackers to delete arbitrary files, including wp-config.php, leading to remote code execution. DIB organizations using WordPress for sensitive systems face immediate compliance risks and potential data loss if this vulnerability is exploited.

Shame score — The vulnerability allows unauthenticated attackers to delete critical system files, enabling remote code execution, which poses a significant risk to DIB organizations using WordPress.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDir function in all versions up to, and including, 2.4.13. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The scf_get_id_upload endpoint freely issues a valid scf_upload_file_removal nonce to any unauthenticated visitor, and the removal endpoint's secondary hash check is forgeable offline because it relies on a hardcoded salt embedded in the plugin source, meaning neither control presents a real authorization boundary.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.