CRITICAL
9.8 CVE-2026-78657 Published 2 Sept 2026
WordPress SigmaForms Pro File Deletion Bug
Worried this affects one of your servers?
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion.
An unauthenticated attacker can delete arbitrary files on the server by exploiting insufficient file path validation in the delete_submission_files function in versions up to and including 1.4.11.
This vulnerability can lead to remote code execution if a critical file like wp-config.php is deleted.
Reference: CVE-2026-78657 on NVD
← Back to Security News