Executive brief
SigmaForms Pro is a WordPress plugin that generates forms using AI. The plugin fails to properly validate file paths when administrators delete form submissions, allowing unauthenticated attackers to delete arbitrary files from the server by submitting a malicious path through a form upload field. By deleting critical files like wp-config.php, an attacker can take over the entire WordPress site or achieve remote code execution.
Technical details
The vulnerability is a path traversal flaw in the delete_submission_files function that fails to validate or sanitize file paths before deletion. An unauthenticated attacker can craft a malicious file path (e.g., using traversal sequences like "../../") and submit it through a form upload field; the malicious path is stored in the database. When an administrator later deletes the submission record from the WordPress admin panel, the delete_submission_files function processes the stored path without proper validation and deletes the arbitrary file on the server. This affects all versions up to and including 1.4.11. No patch information is currently available.
Affected products
- BdThemes SigmaForms Pro up to and including 1.4.11
Timeline
- 2026-09-02: disclosed