Critical Vulnerability in SigmaForms Pro – AI Generated Forms Plugin for WordPress: Arbitrary File Deletion
A critical vulnerability, CVE-2026-78657, with a CVSS score of 9.8, was discovered in the SigmaForms Pro – AI Generated Forms plugin for WordPress. This vulnerability allows unauthenticated attackers to delete arbitrary files on the server due to insufficient file path validation in the delete_submission_files function. This can lead to remote code execution when a critical file, such as wp-config.php, is deleted. The vulnerability affects all versions up to and including 1.4.11 of the plugin.