PT-2026-84600 · WordPress · Sigmaforms-Pro

·

CVE-2026-78657

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SigmaForms Pro – AI Generated Forms versions prior to 1.4.12
Description Insufficient file path validation in the delete submission files() function allows unauthenticated attackers to delete arbitrary files on the server. This is achieved by submitting a malicious path traversal URL via a form upload field, which is then stored in the database. The deletion is triggered when an administrator removes the submission record from the admin panel. Deleting critical files, such as wp-config.php, can lead to remote code execution.
Recommendations Update SigmaForms Pro – AI Generated Forms to version 1.4.12 or later. As a temporary mitigation, restrict the use of the delete submission files() function until the update is applied.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78657

Affected Products

Sigmaforms-Pro