Arbitrary File Deletion in RapiSafe File Upload Plugin for WordPress
CVE-2026-14484

9.1CRITICAL

What is CVE-2026-14484?

The RapiSafe plugin, designed for secure multi-file uploads in Contact Form 7 on WordPress, is afflicted by a vulnerability that allows attackers to exploit insufficient file path validation within the handleAjaxRemoveUpload function. This vulnerability affects all versions up to 1.0.4, enabling unauthenticated users to delete arbitrary files from the server, potentially leading to severe ramifications such as remote code execution. The nonce, which users must provide to activate the file removal handler, is readily accessible in public-facing JavaScript, making it obtainable to any visitor on pages rendering the RapiSafe upload field.

Affected Version(s)

RapiSafe – Secure Multi File Upload for Contact Form 7 0 <= 1.0.4

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Spy0x7
.