CVE-2026-78834
CMSimple · CoAuthors plugin
A code execution vulnerability in the CMSimple CoAuthors plugin allows authenticated low-privileged users to achieve server-side execution via crafted content imports.
Executive summary
A high-severity code execution vulnerability in the CMSimple CoAuthors plugin allows authenticated attackers to compromise server integrity.
Vulnerability
This vulnerability allows an authenticated low-privileged user to trigger server-side code execution by referencing malicious external or uploaded text content through the content import feature. The attack requires authenticated access to the system, specifically the ability to modify page content.
Business impact
The ability to perform remote code execution poses a severe risk to organizational infrastructure, potentially leading to full system compromise, data theft, or complete service disruption. With a CVSS score of 8.8, this vulnerability is classified as high, reflecting the significant impact on confidentiality, integrity, and availability if successfully exploited by a malicious actor within the environment.
Remediation
Immediate Action: Since a specific patch is not currently identified, users should disable the CoAuthors plugin or restrict access to the content import feature until the vendor releases a security update.
Proactive Monitoring: Monitor server logs for unusual file execution patterns, unexpected outbound network connections originating from the CMS server, or unauthorized modifications to page content.
Compensating Controls: Implement strict Web Application Firewall (WAF) rules to filter malicious input and restrict file uploads to trusted sources only, effectively limiting the attack surface for this injection point.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for complete system takeover, organizations using CMSimple with the CoAuthors plugin must treat this as a high-priority risk. Immediately audit user permissions to ensure only trusted individuals can modify page content, and disable the plugin functionality until an official update is provided by the vendor.
More CMSimple CVEs
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written