A security flaw, tracked as CVE-2026-14484, has been found in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, which impacts all versions up to and including 1.0.4. The plugin does not properly validate file paths when handling file deletion requests, making it possible for anyone without an account on your site to delete any files stored on your web server. This is a high-risk issue because deleting specific critical files, such as WordPress’s core wp-config.php file, can allow attackers to take full control of your site and run harmful code on it. The security token needed to trigger the file deletion feature is publicly visible in the code that loads on any page with this plugin’s upload field, so any visitor to your site could access it and use it to exploit the vulnerability.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14484