CVE-2026-14484 (matched: wordpress)

  • Monday, 17th August, 2026
  • 04:03am

A security flaw has been identified in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, impacting all versions up to and including 1.0.4. The vulnerability stems from poor validation of file paths, which allows unauthenticated attackers (people who do not have login access to your website) to delete any files stored on your site's server.

This is a serious risk because deleting critical site files, such as wp-config.php (a core WordPress configuration file), can let attackers take full control of your site, run malicious code, steal visitor or customer data, or alter your site's published content. The security token designed to block unauthorized use of the file deletion feature is publicly visible in the site code on any page that includes a RapiSafe upload field for Contact Form 7, meaning any random visitor to that page can obtain it and exploit the vulnerability.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14484

« Back