{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rapisafe--secure-multi-file-upload-for-contact-form-7--1.0.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-14484"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RapiSafe – Secure Multi File Upload for Contact Form 7 (\u003c= 1.0.4)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe RapiSafe - Secure Multi File Upload for Contact Form 7 plugin for WordPress is affected by an arbitrary file deletion vulnerability identified as CVE-2026-14484. The vulnerability resides in the 'handleAjaxRemoveUpload' function, which fails to properly validate file paths during the deletion process. Because the security nonce required to authorize the AJAX call is exposed globally in the client-side JavaScript object 'RSMFCF7Vars.nonce' on all pages where the plugin is active, any unauthenticated user can craft malicious requests to delete files on the host server. An attacker can leverage this primitive to delete sensitive configuration files such as 'wp-config.php', which often results in the site reverting to an unconfigured state or forcing a re-installation that can lead to remote code execution. This vulnerability affects all versions up to and including 1.0.4.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker navigates to a public-facing WordPress page that utilizes the RapiSafe plugin.\u003c/li\u003e\n\u003cli\u003eAttacker inspects the page source or browser console to locate the 'RSMFCF7Vars.nonce' variable.\u003c/li\u003e\n\u003cli\u003eAttacker extracts the valid security nonce required for plugin AJAX requests.\u003c/li\u003e\n\u003cli\u003eAttacker constructs an HTTP POST request targeting the 'handleAjaxRemoveUpload' endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker provides the path to a sensitive target file (e.g., /var/www/html/wp-config.php) in the request parameters.\u003c/li\u003e\n\u003cli\u003eThe server validates the stolen nonce as authentic and proceeds with the file deletion process.\u003c/li\u003e\n\u003cli\u003eThe target file is deleted from the server filesystem.\u003c/li\u003e\n\u003cli\u003eAttacker observes site downtime or initiates a malicious WordPress installation process to gain full administrative control (RCE).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to delete arbitrary files on the WordPress server. This typically results in a complete denial of service for the website or, if the site's configuration file is removed, enables the attacker to perform a fresh WordPress installation. Through this installation process, an attacker can gain administrative access to the platform, resulting in full remote code execution and potential data exfiltration. The severity is marked as critical due to the ease of nonce acquisition and the high-impact nature of the resulting file deletion.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the 'RapiSafe - Secure Multi File Upload for Contact Form 7' plugin to the latest available version that addresses CVE-2026-14484.\u003c/li\u003e\n\u003cli\u003eIf an update is not currently available, disable the plugin or restrict access to the affected AJAX endpoints via web application firewall (WAF) rules.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests to the plugin's AJAX handler originating from unauthenticated sessions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T04:16:05Z","date_published":"2026-08-15T04:16:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rapisafe-file-deletion/","summary":"The RapiSafe WordPress plugin contains a vulnerability in its AJAX upload handler allowing unauthenticated attackers to delete arbitrary server files, potentially leading to remote code execution.","title":"Unauthenticated Arbitrary File Deletion in RapiSafe WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-rapisafe-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - RapiSafe – Secure Multi File Upload for Contact Form 7 (\u003c= 1.0.4)","version":"https://jsonfeed.org/version/1.1"}