Executive brief
SigmaForms Pro is a WordPress plugin used to create AI-generated forms for websites. A critical security flaw allows unauthorized individuals to upload malicious files directly to the web server without needing to log in. This could lead to a complete takeover of the website, data theft, or the installation of persistent backdoors.
Technical details
The SigmaForms Pro plugin for WordPress is vulnerable to an unrestricted arbitrary file upload (CWE-434) in versions up to and including 1.4.5. The vulnerability allows an unauthenticated remote attacker to upload dangerous file types, such as PHP scripts, to the server. While the CVSS vector indicates high complexity (AC:H), the lack of authentication requirements (PR:N) and the potential for a changed scope (S:C) make this a high-impact flaw. Successful exploitation can lead to full remote code execution (RCE) and complete site compromise. The issue is resolved in version 1.4.6.
Affected products
- BDthemes SigmaForms Pro – AI Generated Forms <= 1.4.5
Timeline
- 2026-06-07: other: Reported by Nguyen Ba Khanh
- 2026-06-15: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date