CVE-2026-14484 (matched: wordpress)

  • Saturday, 15th August, 2026
  • 22:04pm

A security vulnerability has been identified in the RapiSafe – Secure Multi File Upload for Contact Form 7 WordPress plugin, which adds secure file upload features to Contact Form 7 forms. All versions of the plugin up to and including 1.0.4 are affected by this flaw.

The issue allows unauthenticated attackers (people who do not have admin login access to your website) to delete any files stored on the server that hosts your site. If an attacker deletes a critical core WordPress file such as wp-config.php, this can easily lead to full remote control of your website.

The security check meant to restrict access to the file deletion feature is embedded in public-facing page code for any site visitor to view and copy. This means attackers do not need any special access to exploit this vulnerability.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14484

« Back