What is CVE-2026-14484?
The 'RapiSafe – Secure Multi File Upload for Contact Form 7' plugin for WordPress (up to and including version 1.0.4) is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'handleAjaxRemoveUpload' function. This allows unauthenticated attackers to delete files on the server. Users are advised to update to the latest version immediately.
Azərbaycanca: WordPress-in 'RapiSafe – Secure Multi File Upload for Contact Form 7' pluginində (versiya 1.0.4 və əvvəlki) 'handleAjaxRemoveUpload' funksiyasında kifayət qədər fayl yolu yoxlaması səbəbindən ixtiyari fayl silmə zəifliyi aşkar edilib. Bu, autentifikasiya olunmamış hücumçulara serverdəki faylları silməyə imkan yaradır. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which WordPress plugin is affected by CVE-2026-14484?
CVE-2026-14484 affects the 'RapiSafe – Secure Multi File Upload for Contact Form 7' plugin up to and including version 1.0.4.
What can an unauthenticated attacker do by exploiting CVE-2026-14484?
An unauthenticated attacker can delete arbitrary files on the server due to insufficient file path validation in the 'handleAjaxRemoveUpload' function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.