A security flaw has been identified in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, which impacts all versions up to and including 1.0.4. This flaw allows anyone who does not have login access to your website to delete any files stored on your site's server.
If an attacker deletes a critical core WordPress file, such as the wp-config.php file that stores essential site configuration data, they can gain full control of your website. The security check meant to restrict access to the file deletion feature is accidentally exposed in public website code on any page that uses this plugin's upload field, meaning any visitor to those pages can retrieve it and use it to exploit the flaw.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14484