← WordPress Vulnerabilities
WordPress security by component

SigmaForms Pro – AI Generated Forms

SigmaForms Pro – AI Generated Forms (sigmaforms-pro) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 9.8.

Plugin slug: sigmaforms-pro

CVE-2026-78657: SigmaForms Pro permits unauthenticated arbitrary file deletion

SigmaForms Pro through 1.4.11 accepts a path-traversal value through a public form upload field and stores it with the submission. When an administrator later deletes that submission, delete_submission_files() uses the stored path without adequate validation and can delete an arbitrary server file. Deleting a critical file such as wp-config.php can lead to site compromise or remote code execution.

PublishedSep 02, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for sigmaforms-pro
Safe version
Sep 02, 2026 CVE-2026-78657
SigmaForms Pro permits unauthenticated arbitrary file deletion
SigmaForms Pro through 1.4.11 accepts a path-traversal value through a public form upload field and stores it with the submission. When an administrator later deletes that submission, delete_submission_files() uses the stored path without adequate validation and can delete an arbitrary server file. Deleting a critical file such as wp-config.php can lead to site compromise or remote code execution.
See mitigation notes
CVE9.8
NVDPending
Aug 29, 2026 CVE-2026-14494
SigmaForms Pro unrestricted form uploads permit unauthenticated code execution
SigmaForms Pro through 1.4.5 grants unfiltered_upload during handle_form_submission() and bypasses MIME validation when allowed_file_types is not configured. An unauthenticated visitor can upload executable content and run code on the server. Default Job Application, Support Ticket, and Wholesale Application templates include unrestricted upload fields, making the path available on a default installation using those templates.
See mitigation notes
CVE9.8
NVDPending
Jun 17, 2026 CVE-2026-52705
SigmaForms Pro – AI Generated Forms: Dangerous file upload
SigmaForms Pro – AI Generated Forms is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 1.4.5.
1.4.6
CVE9.0
NVDPending