A security vulnerability tracked as CVE-2026-14484 has been identified in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, which impacts all versions of the plugin up to and including 1.0.4. This plugin is designed to let visitors upload files through Contact Form 7 forms on WordPress sites.
The flaw stems from the plugin not properly validating file paths when processing file deletion requests. This makes it possible for any visitor to your site, even without a login or account, to delete any files stored on your web server. If an attacker deletes a critical core file such as WordPress’s wp-config.php configuration file, they can gain full control of your website.
The security credential required to trigger this file deletion function is accidentally exposed in public-facing website code on every page that includes a Contact Form 7 form with a RapiSafe upload field. This means any unauthenticated visitor can easily access this credential to launch an attack.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14484