← Terug naar overzicht

The SigmaForms Pro – AI Generated Forms plugin for WordPress contains a critical vulnerability allowing arbitrary file deletion due to insufficient file path validation in the delete_submission_files function. All versions up to and including 1.4.11 are affected. Unauthenticated attackers can exploit this by submitting malicious path traversal URLs via form upload fields, which are stored in the database. Deletion is triggered when an administrator removes a submission record from the admin panel. This can lead to remote code execution if critical files such as wp-config.php are deleted. The vulnerability requires no authentication to exploit, making it particularly dangerous. The issue is tracked as CVE-2026-78657 and has been documented by both NVD and Wordfence.

Affected products

  • SigmaForms Pro – AI Generated Forms plugin for WordPress (versions up to 1.4.11)

Related CVE's

  • CVE-2026-78657

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities