CVE-2026-14484 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 10:04am

A security flaw (identified as CVE-2026-14484) affects the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, impacting all versions up to and including 1.0.4. This plugin is designed to let visitors upload multiple files through Contact Form 7 forms on your WordPress site. The issue comes from the plugin not properly verifying file paths when handling requests to delete uploaded files. This makes it possible for anyone visiting your site, even if they are not logged in, to delete any file stored on your website's server. If an attacker deletes the correct core file, such as your site's main WordPress configuration file (wp-config.php), they can gain full control of your site and run their own malicious code on it. The security code that is supposed to block unauthorized use of this file deletion feature is accidentally visible in the public code of any page that uses a RapiSafe upload field with Contact Form 7, so any site visitor can access this code and exploit the flaw without needing special permissions.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14484

« Back