RapiSafe WordPress Plugin Vulnerability: Critical CVE-2026-14484
- Severity
- CRITICAL
- CVSS
- 9.1
- Affected component
- rapisafe – secure multi file upload for contact form 7 (wordpress)
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the RapiSafe, Secure Multi File Upload for Contact Form 7 plugin for WordPress. Versions up to and including 1.0.4 are reportedly affected.
What happened
The RapiSafe, Secure Multi File Upload for Contact Form 7 plugin for WordPress is under investigation for a critical vulnerability. This vulnerability, tracked as CVE-2026-14484, allows for arbitrary file deletion due to insufficient file path validation. This can potentially lead to remote code execution if critical files are deleted. The vulnerability is present in all versions up to, and including, 1.0.4.
The issue arises from the handleAjaxRemoveUpload function, which does not properly validate file paths. The nonce required to invoke the removal handler is exposed in public-facing JavaScript, making it obtainable by any unauthenticated visitor. This exposure allows unauthenticated attackers to delete arbitrary files on the server.
What to do about it
- Monitor the primary sources for updates on a patched version.
- Review server files for any signs of tampering or unauthorized deletions.
- Consider disabling the RapiSafe plugin until a patched version is available.
- Stay informed by consulting the primary sources listed below for the latest information.
How 0Day would have caught this
rapisafe – secure multi file upload for contact form 7 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the RapiSafe, Secure Multi File Upload for Contact Form 7 plugin for WordPress and your version is 1.0.4 or earlier, you are reportedly affected.
What should I do right now?
Monitor the primary sources for updates on a patched version. Review your server files for any signs of tampering or unauthorized deletions. Consider disabling the RapiSafe plugin until a patched version is available.
Is there a patched version available?
No official fix has been published yet. Monitor the primary sources for updates.