CRITICAL 9.8 CVE-2026-78657 Published 2 Sept 2026

WordPress SigmaForms Pro File Deletion Bug

Worried this affects one of your servers?

The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion.

An unauthenticated attacker can delete arbitrary files on the server by exploiting insufficient file path validation in the delete_submission_files function in versions up to and including 1.4.11.

This vulnerability can lead to remote code execution if a critical file like wp-config.php is deleted.

Reference: CVE-2026-78657 on NVD

← Back to Security News