SECURITYCRITICALCVE-2026-14484

CVE-2026-14484: WordPress RapiSafe Plugin Arbitrary File Deletion

Critical unauthenticated arbitrary file deletion in WordPress RapiSafe plugin v1.0.4 and below allows attackers to delete any file on the server.

Dylan H.

Security Team

August 15, 2026
3 min read
CVE-2026-14484: WordPress RapiSafe Plugin Arbitrary File Deletion

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • RapiSafe – Secure Multi File Upload for Contact Form 7 <= 1.0.4

Executive Summary

A critical unauthenticated arbitrary file deletion vulnerability has been disclosed in the RapiSafe – Secure Multi File Upload for Contact Form 7 WordPress plugin. Tracked as CVE-2026-14484 with a CVSS score of 9.1 (Critical), the flaw exists in all versions up to and including 1.0.4 and allows any unauthenticated attacker to delete arbitrary files on the server — including wp-config.php, which would effectively destroy the WordPress installation.


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-14484
CVSS Score9.1 (Critical)
TypeArbitrary File Deletion
Attack VectorNetwork
AuthenticationNone required
Affected PluginRapiSafe – Secure Multi File Upload for Contact Form 7
Affected VersionsAll versions <= 1.0.4
Patch AvailableCheck plugin repository for updated version

Technical Details

The vulnerability resides in the handleAjaxRemoveUpload function of the RapiSafe plugin. This AJAX handler is registered on wp_ajax_nopriv_*, meaning it is accessible to unauthenticated users. The function is responsible for removing uploaded files before a contact form is submitted, but it performs insufficient file path validation.

Because no sanitization or restriction is applied to the file path parameter, an attacker can supply a crafted path using directory traversal sequences (e.g., ../../) to escape the upload directory and target any file readable or writable by the web server process. Deleting wp-config.php is the most impactful attack, as it causes WordPress to enter installation mode and can expose database credentials from server backups.

Attack Flow

1. Attacker identifies a WordPress site running RapiSafe plugin <= 1.0.4
2. Crafts an AJAX request to the handleAjaxRemoveUpload endpoint
3. Supplies a path-traversal string pointing to a target file (e.g. wp-config.php)
4. Server deletes the targeted file without authentication or path validation
5. Site may become unavailable or enter re-installation mode

Impact

  • Site takeover via re-installation: Deleting wp-config.php causes WordPress to believe it is not configured, prompting re-installation. An attacker completing re-installation gains full admin access.
  • Data destruction: Any file writable by the web server process — uploads, themes, plugins, or core files — can be permanently deleted.
  • Denial of service: Deletion of critical files can render the site inoperable.

Affected Versions

PluginAffected VersionsStatus
RapiSafe – Secure Multi File Upload for Contact Form 7<= 1.0.4Patch available

Remediation

  1. Update immediately: Install the latest version of the RapiSafe plugin from the WordPress plugin repository.
  2. If no patch is available: Deactivate and remove the plugin until a patched version is released.
  3. Audit file permissions: Ensure the web server process does not have write access to files outside the wp-content/uploads directory where possible.
  4. Review server logs: Check for unexpected AJAX requests to wp_ajax_nopriv_* endpoints targeting file removal handlers.
  5. Restore from backup: If exploitation is suspected, restore wp-config.php and other critical files from a known-good backup.

Detection

Look for HTTP POST requests in web server access logs targeting WordPress admin-ajax with the action matching the plugin's removal handler, particularly those containing directory traversal patterns (../, ..%2F, %2e%2e%2f) in parameters.


References