The SigmaForms Pro – AI Generated Forms plugin for WordPress contains a critical arbitrary file deletion vulnerability in the delete_submission_files function. All versions up to and including 1.4.11 are affected. Unauthenticated attackers can exploit insufficient file path validation to delete arbitrary files on the server. The attack vector involves submitting a malicious path traversal URL via a form upload field, which is stored in the database. Deletion is triggered when an administrator removes the submission record from the admin panel. This can lead to remote code execution, for example by deleting wp-config.php, which may destabilize the WordPress installation and open the door to further exploitation. No authentication is required for the initial injection phase, making this accessible to a wide range of attackers.