Arbitrary File Deletion in RapiSafe File Upload Plugin for WordPress
CVE-2026-14484
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 August 2026
What is CVE-2026-14484?
The RapiSafe plugin, designed for secure multi-file uploads in Contact Form 7 on WordPress, is afflicted by a vulnerability that allows attackers to exploit insufficient file path validation within the handleAjaxRemoveUpload function. This vulnerability affects all versions up to 1.0.4, enabling unauthenticated users to delete arbitrary files from the server, potentially leading to severe ramifications such as remote code execution. The nonce, which users must provide to activate the file removal handler, is readily accessible in public-facing JavaScript, making it obtainable to any visitor on pages rendering the RapiSafe upload field.
Affected Version(s)
RapiSafe β Secure Multi File Upload for Contact Form 7 0 <= 1.0.4