{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sigmaforms-pro--ai-generated-forms--1.4.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:sigmaforms_pro_ai_generated_forms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-78657"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SigmaForms Pro – AI Generated Forms (\u003c= 1.4.11)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","vulnerability","arbitrary-file-deletion"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe SigmaForms Pro - AI Generated Forms plugin for WordPress, in versions up to and including 1.4.11, is susceptible to an unauthenticated arbitrary file deletion vulnerability. This flaw resides in the delete_submission_files function, which fails to properly validate file paths during the deletion process. An attacker can inject a path traversal sequence into an upload field of a form. This malicious path is saved into the database within a submission record. When a site administrator later performs a cleanup or removes the submission record from the WordPress admin panel, the plugin processes the path and deletes the targeted file.\u003c/p\u003e\n\u003cp\u003eBy chaining this vulnerability with the deletion of critical WordPress configuration files such as wp-config.php, an attacker can force a re-installation of the application, potentially leading to remote code execution. Because the malicious trigger occurs during an administrative action, there is a delayed execution window between the initial malicious submission and the final file deletion.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running SigmaForms Pro version 1.4.11 or lower.\u003c/li\u003e\n\u003cli\u003eAttacker submits a form containing an upload field.\u003c/li\u003e\n\u003cli\u003eAttacker inputs a path traversal string (e.g., ../../../wp-config.php) into the upload field payload.\u003c/li\u003e\n\u003cli\u003eThe malicious string is stored in the database as a submission record by the plugin.\u003c/li\u003e\n\u003cli\u003eAn administrator logs into the WordPress dashboard.\u003c/li\u003e\n\u003cli\u003eThe administrator selects the malicious submission record and triggers a delete action.\u003c/li\u003e\n\u003cli\u003eThe plugin executes delete_submission_files, invoking the file deletion logic with the attacker-supplied path.\u003c/li\u003e\n\u003cli\u003eThe targeted file is deleted from the server filesystem.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to delete arbitrary files on the WordPress server. This can cause significant service disruption or lead to full system compromise if attackers delete critical files like wp-config.php to initiate a site re-installation. The vulnerability affects all users running versions 1.4.11 or earlier of the SigmaForms Pro plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate SigmaForms Pro - AI Generated Forms to the latest version (v1.4.12 or higher) to remediate CVE-2026-78657.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous POST requests to form submission endpoints containing directory traversal patterns like '../'.\u003c/li\u003e\n\u003cli\u003eRestrict file system permissions for the WordPress application user to prevent deletion of sensitive files outside of the intended upload directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T07:12:21Z","date_published":"2026-09-02T07:12:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sigmaforms-pro-file-deletion/","summary":"The SigmaForms Pro WordPress plugin is vulnerable to arbitrary file deletion via path traversal in the delete_submission_files function, allowing unauthenticated attackers to delete critical server files and potentially achieve remote code execution.","title":"Arbitrary File Deletion Vulnerability in SigmaForms Pro","url":"https://feed.craftedsignal.io/briefs/2026-09-sigmaforms-pro-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - SigmaForms Pro – AI Generated Forms (\u003c= 1.4.11)","version":"https://jsonfeed.org/version/1.1"}