CVE-2026-14484 (matched: wordpress)

  • Monday, 17th August, 2026
  • 10:04am

A critical security flaw has been found in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, affecting all versions up to and including 1.0.4. The plugin fails to properly validate file paths when processing file deletion requests, and the secret security token required to trigger this deletion feature is accidentally exposed in public website code on any page that includes a RapiSafe upload field for Contact Form 7.

This means any unauthenticated visitor to your site (no login or special access needed) can exploit the flaw to delete any files stored on your website's server. If an attacker deletes a critical core file such as your site's main configuration file, they can gain full control of your site to run unauthorized, malicious code.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14484

« Back