WORDPRESS · AUGUST 2026 · EARLY WARNING

RapiSafe WordPress Plugin Vulnerability: Critical CVE-2026-14484

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.1
Affected component
rapisafe – secure multi file upload for contact form 7 (wordpress)
Patched version
Not yet available
CVE-2026-14484

An early warning has been issued for a critical vulnerability in the RapiSafe, Secure Multi File Upload for Contact Form 7 plugin for WordPress. Versions up to and including 1.0.4 are reportedly affected.

What happened

The RapiSafe, Secure Multi File Upload for Contact Form 7 plugin for WordPress is under investigation for a critical vulnerability. This vulnerability, tracked as CVE-2026-14484, allows for arbitrary file deletion due to insufficient file path validation. This can potentially lead to remote code execution if critical files are deleted. The vulnerability is present in all versions up to, and including, 1.0.4.

The issue arises from the handleAjaxRemoveUpload function, which does not properly validate file paths. The nonce required to invoke the removal handler is exposed in public-facing JavaScript, making it obtainable by any unauthenticated visitor. This exposure allows unauthenticated attackers to delete arbitrary files on the server.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If rapisafe – secure multi file upload for contact form 7 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the RapiSafe, Secure Multi File Upload for Contact Form 7 plugin for WordPress and your version is 1.0.4 or earlier, you are reportedly affected.

What should I do right now?

Monitor the primary sources for updates on a patched version. Review your server files for any signs of tampering or unauthorized deletions. Consider disabling the RapiSafe plugin until a patched version is available.

Is there a patched version available?

No official fix has been published yet. Monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats